CVE-2021-21484: Critical severity sap hana database vulnerability
Published Mar 9, 2021
·Updated
LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bind.
Affected Software
1 affected component
SAP HANA=2.0
Event History
Mar 9, 2021
CVE Published
via MITRE·02:11 PM
Data Sourced
via MITRE·02:11 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-21484.
2
What is the severity of CVE-2021-21484?
The severity of CVE-2021-21484 is critical with a score of 9.8.
3
Which versions of SAP HANA Database are affected by this vulnerability?
This vulnerability affects SAP HANA Database version 2.0.
4
How can the LDAP authentication bypass be exploited?
The LDAP authentication bypass can be exploited if the attached LDAP directory server is configured to enable unauthenticated bind.
5
Is there a fix available for CVE-2021-21484?
Yes, SAP has released a fix for CVE-2021-21484. Please refer to the SAP support page for more information.