Hana SAP Hana

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in SAP Hana.

By the Year

In 2026 there have been 0 vulnerabilities in SAP Hana. Last year, in 2025 Hana had 2 security vulnerabilities published. Right now, Hana is on track to have less security vulnerabilities in 2026 than it did last year.




Year Vulnerabilities Average Score
2026 0 0.00
2025 2 6.35
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 1 9.80
2020 0 0.00
2019 2 6.35
2018 5 5.84

It may take a day or so for new Hana vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent SAP Hana Security Vulnerabilities

SAP HANA JDBC Client Code Loading via Unvalidated Conn Props
CVE-2025-42895 6.9 - Medium - November 11, 2025

Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply crafted parameters that lead to unauthorized code loading, resulting in low impact on confidentiality and integrity and high impact on availability of the application.

Code Injection

SAP HANA 2.0 hdbrss Unauth Remote Function Disclosure
CVE-2025-42885 5.8 - Medium - November 11, 2025

Due to missing authentication, SAP HANA 2.0 (hdbrss) allows an unauthenticated attacker to call a remote-enabled function that will enable them to view information. As a result, it has a low impact on the confidentiality but no impact on the integrity and availability of the system.

Missing Authentication for Critical Function

LDAP authentication in SAP HANA Database version 2.0
CVE-2021-21484 9.8 - Critical - March 09, 2021

LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bind.

AuthZ

The administrator of SAP HANA database, before versions 1.0 and 2.0
CVE-2019-0357 6.7 - Medium - September 10, 2019

The administrator of SAP HANA database, before versions 1.0 and 2.0, can misuse HANA to execute commands with operating system "root" privileges.

SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source
CVE-2019-0284 6 - Medium - April 10, 2019

SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source. The attacker can call SLDREG with an XML file containing a reference to an XML External Entity (XXE). This can cause SLDREG to, for example, continuously loop, read arbitrary files and even send local files.

XXE

The security audit log of SAP HANA
CVE-2018-2497 2.7 - Low - December 11, 2018

The security audit log of SAP HANA, versions 1.0 and 2.0, does not log SELECT events if these events are part of a statement with the syntax CREATE TABLE <table_name> AS SELECT.

SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate XML
CVE-2018-2465 7.5 - High - September 11, 2018

SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate XML. By exploiting, an unauthorized hacker can cause the database server to crash.

Improper Input Validation

In systems using the optional capture & replay functionality of SAP HANA
CVE-2018-2402 8.4 - High - March 14, 2018

In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver trace files of the control system. An attacker with the required authorizations on the control system may be able to access the user credentials and gain unauthorized access to data in the captured or target system.

Information Disclosure

Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access information which would otherwise be restricted
CVE-2018-2369 5.3 - Medium - February 14, 2018

Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access information which would otherwise be restricted. An attacker can misuse the authentication function of the SAP HANA server on its SQL interface and disclose 8 bytes of the server process memory. The attacker cannot influence or predict the location of the leaked memory.

A remote unauthenticated attacker
CVE-2018-2362 5.3 - Medium - January 09, 2018

A remote unauthenticated attacker, SAP HANA 1.00 and 2.00, could send specially crafted SOAP requests to the SAP Startup Service and disclose information such as the platform's hostname.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for SAP Hana or by SAP? Click the Watch button to subscribe.

SAP
Vendor

SAP Hana
Product

subscribe