PT-2021-14550 · Sap · Sap Hana Database
Published
2021-03-09
·
Updated
2021-03-16
·
CVE-2021-21484
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP HANA Database version 2.0
Description
The issue allows LDAP authentication in SAP HANA Database to be bypassed if the attached LDAP directory server is configured to enable unauthenticated bind.
Recommendations
For SAP HANA Database version 2.0, ensure the attached LDAP directory server is configured to disable unauthenticated bind to prevent authentication bypass.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Hana Database