← Back to CVE List
Vulnerability Intelligence Report
Memory Corruption vulnerability in SAP CommonCryptoLib

CVE-2023-40308

SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any information.

No Active Exploit Signals
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:0.62%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-787 ↗CWE-787 Out-of-bounds Write

Affected Products & Versions

Vendor Product Affected Versions
SAP_SE SAP CommonCryptoLib 8 (affected)
SAP_SE SAP NetWeaver AS ABAP, SAP NetWeaver AS Java and ABAP Platform of S/4HANA on-premise KERNEL 7.22 (affected), KERNEL 7.53 (affected), KERNEL 7.54 (affected), KERNEL 7.77 (affected), KERNEL 7.85 (affected), KERNEL 7.89 (affected), KERNEL 7.91 (affected), KERNEL 7.92 (affected), KERNEL 7.93 (affected), KERNEL 8.04 (affected), KERNEL64UC 7.22 (affected), KERNEL64UC 7.22EXT (affected), KERNEL64UC 7.53 (affected), KERNEL64UC 8.04 (affected), KERNEL64NUC 7.22 (affected), KERNEL64NUC 7.22EXT (affected)
SAP_SE SAP Web Dispatcher 7.22EXT (affected), 7.53 (affected), 7.54 (affected), 7.77 (affected), 7.85 (affected), 7.89 (affected)
SAP_SE SAP Content Server 6.50 (affected), 7.53 (affected), 7.54 (affected)
SAP_SE SAP HANA Database 2.00 (affected)
SAP_SE SAP Host Agent 722 (affected)
SAP_SE SAP Extended Application Services and Runtime (XSA) SAP_EXTENDED_APP_SERVICES 1 (affected), XS_ADVANCED_RUNTIME 1.00 (affected)
SAP_SE SAPSSOEXT 17 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.622%

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySAP SE · Vendor · Germany
Reserved2023-08-14T07:36:04
Published2023-09-12T01:21:15
Last Updated2024-09-26T18:22:53

LINK COPIED TO CLIPBOARD