Skip links
Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-26834 Improper authentication in SAP HANA database, SAP security note 2978768

Description

The SAP HANA database does not correctly validate the user name when performing SAML bearer token-based user authentication. It is possible to manipulate a valid existing SAML bearer token to authenticate as a user whose name is identical to the truncated user name for whom the SAML bearer token was issued.

Available fix and Supported packages

  • HDB | 1.00 | 1.00
  • HDB | 2.00 | 2.00
  • SAP HANA DATABASE 1.00 | SP122 | 000033
  • SAP HANA DATABASE 2.0 | SP048 | 000003
  • SAP HANA DATABASE 2.0 | SP053 | 000000

Affected component

    HAN-DB-SEC
    SAP HANA Security & User Management

CVSS

Score: 4.2
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

PoC

Detailed vulnerability information added to RedRays Security Platform. Contact support@redrays.io for details.

URL

https://launchpad.support.sap.com/#/notes/2978768

TAGS

#Broken-Authentication
#&160-CVE-2020-26834

Explore More

SAP Security Patch Day RedRays

SAP Security Patch Day – April 2025

On April 8, 2025, SAP released its monthly Security Patch Day updates, addressing 19 new vulnerabilities across various SAP products and components.

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.