SAP hana database是德国SAP公司的一个高性能内存数据库系统。 SAP HANA Database存在侧信道信息泄露漏洞,该漏洞源于响应差异问题,可能导致未经身份验证的用户发送特制请求枚举有效用户账户和电子邮件地址,对机密性造成低影响。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SAP_SE | SAP HANA Extended Application Services classic model (User Self Service) | HDB 2.00 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP HANA Extended Application Services classic model (User Self Service) | HDB 2.00 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44747 | 9.9 CRITICAL | Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP |
| CVE-2026-27690 | 9.1 CRITICAL | HTTP Request Smuggling in SAP Approuter |
| CVE-2026-44761 | 9.1 CRITICAL | Insecure Sample Credentials in SAP Commerce Cloud |
| CVE-2026-0487 | 8.4 HIGH | DLL Hijacking vulnerability in SAProuter on Microsoft Windows |
| CVE-2026-44752 | 8.2 HIGH | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java(Configur |
| CVE-2026-44745 | 8.1 HIGH | Open Redirect vulnerability in SAP Approuter |
| CVE-2026-58233 | 7.6 HIGH | Remote Code Execution vulnerability in SAP Change and Transport System Attach Tool (ctsatt |
| CVE-2026-44767 | 6.1 MEDIUM | Allowlist Bypass in setThemeRoot() Enables Cross-Origin CSS Injection |
| CVE-2026-44759 | 6.1 MEDIUM | Cross Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal |
| CVE-2026-44769 | 5.5 MEDIUM | SQL Injection vulnerability in SAP S/4HANA Project Management (PPM-PRO) |
| CVE-2026-44760 | 4.7 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applica |
| CVE-2026-44771 | 4.3 MEDIUM | Missing Authorization check in SAP S/4HANA (Draft operation) |
| CVE-2026-44770 | 4.3 MEDIUM | Missing Authorization check in SAP S/4 HANA (Create Single Payment) |
| CVE-2026-44768 | 4.1 MEDIUM | Security misconfiguration in SAP CRM (WebClient UI) |
No comments yet