← Back to CVE List
Vulnerability Intelligence Report
Missing Authorization check in SAP CommonCryptoLib

CVE-2023-40309

SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a particular user group as well as read, modify or delete restricted data.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:0.75%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-863 ↗CWE-863: Incorrect Authorization

Affected Products & Versions

Vendor Product Affected Versions
SAP_SE SAP CommonCryptoLib 8 (affected)
SAP_SE SAP NetWeaver AS ABAP, SAP NetWeaver AS Java and ABAP Platform of S/4HANA on-premise KERNEL 7.22 (affected), KERNEL 7.53 (affected), KERNEL 7.54 (affected), KERNEL 7.77 (affected), KERNEL 7.85 (affected), KERNEL 7.89 (affected), KERNEL 7.91 (affected), KERNEL 7.92 (affected), KERNEL 7.93 (affected), KERNEL 8.04 (affected), KERNEL64UC 7.22 (affected), KERNEL64UC 7.22EXT (affected), KERNEL64UC 7.53 (affected), KERNEL64UC 8.04 (affected), KERNEL64NUC 7.22 (affected), KERNEL64NUC 7.22EXT (affected)
SAP_SE SAP Web Dispatcher 7.22EXT (affected), 7.53 (affected), 7.54 (affected), 7.77 (affected), 7.85 (affected), 7.89 (affected)
SAP_SE SAP Content Server 6.50 (affected), 7.53 (affected), 7.54 (affected)
SAP_SE SAP HANA Database 2.00 (affected)
SAP_SE SAP Host Agent 722 (affected)
SAP_SE SAP Extended Application Services and Runtime (XSA) SAP_EXTENDED_APP_SERVICES 1 (affected), XS_ADVANCED_RUNTIME 1.00 (affected)
SAP_SE SAPSSOEXT 17 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.748%

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySAP SE · Vendor · Germany
Reserved2023-08-14T07:36:04
Published2023-09-12T02:21:19
Last Updated2024-09-28T22:10:46

LINK COPIED TO CLIPBOARD