CVE-2020-26834: Medium severity sap hana sps09 vulnerability
SAP HANA Database, version - 2.0, does not correctly validate the username when performing SAML bearer token-based user authentication. It is possible to manipulate a valid existing SAML bearer token to authenticate as a user whose name is identical to the truncated username for whom the SAML bearer token was issued.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this SAP HANA Database vulnerability?
The vulnerability ID for this SAP HANA Database vulnerability is CVE-2020-26834.
What is the severity of CVE-2020-26834?
The severity of CVE-2020-26834 is medium with a CVSS score of 5.4.
What is the affected software for CVE-2020-26834?
The affected software for CVE-2020-26834 is SAP HANA Database version 2.0.
What is the impact of CVE-2020-26834?
CVE-2020-26834 allows an attacker to authenticate as a user by manipulating a valid existing SAML bearer token.
Is there a fix available for CVE-2020-26834?
Yes, SAP has released a note with the fix for CVE-2020-26834. Please refer to the SAP note for more details.