Filtered by vendor Sap Subscriptions
Filtered by product Hana-client Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-42895 1 Sap 1 Hana-client 2025-11-12 6.9 Medium
Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply crafted parameters that lead to unauthorized code loading, resulting in low impact on confidentiality and integrity and high impact on availability of the application.
CVE-2024-45277 2 Sap, Sap Se 2 Hana-client, Sap Hana Client 2024-11-14 4.3 Medium
The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability allowing an attacker to add arbitrary properties to global object prototypes. This is due to improper user input sanitation when using the nestTables feature causing low impact on the availability of the application. This has no impact on Confidentiality and Integrity.