Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-21474

Опубликовано: 09 фев. 2021
Источник: nvd
CVSS3: 6.5
CVSS2: 5.5
EPSS Низкий

Описание

SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion issued for an SAP HANA instance might be able to tamper with it and alter it in a way that the digest continues to be the same and without invalidating the digital signature, this allows them to impersonate as user in HANA database and be able to read the contents in the database.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sap:hana_database:1.00:*:*:*:*:*:*:*
cpe:2.3:a:sap:hana_database:2.00:*:*:*:*:*:*:*

EPSS

Процентиль: 36%
0.00152
Низкий

6.5 Medium

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion issued for an SAP HANA instance might be able to tamper with it and alter it in a way that the digest continues to be the same and without invalidating the digital signature, this allows them to impersonate as user in HANA database and be able to read the contents in the database.

EPSS

Процентиль: 36%
0.00152
Низкий

6.5 Medium

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-326