← Back

CVE-2023-40308

nvd nist
Published: Sep 12, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any information.

Affected (47)

9 products
Commoncryptolib
Content Server
Hana Database
Host Agent
Netweaver Application Server Abap
Netweaver Application Server Java
Sapssoext
Web Dispatcher
Configuration A
47 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0.0
Sap
Version 6.50
Version 7.53
Version 7.54
Version 1.0
Version 2.0
Version 722
Sap
Version 7.22ext
Version kernel64nuc_7.22
Version kernel64nuc_7.22ext
Version kernel64uc_7.22
Version kernel64uc_7.22ext
Version kernel64uc_7.53
Version kernel64uc_8.04
Version kernel_7.22
Version kernel_7.53
Version kernel_7.54
Version kernel_7.77
Version kernel_7.85
Version kernel_7.89
Version kernel_7.91
Version kernel_7.92
Version kernel_7.93
Version kernel_8.04
Sap
Version kernel64nuc_7.22
Version kernel64nuc_7.22ext
Version kernel64uc_7.22
Version kernel64uc_7.22ext
Version kernel64uc_7.53
Version kernel64uc_8.04
Version kernel_7.22
Version kernel_7.53
Version kernel_7.54
Version kernel_7.77
Version kernel_7.85
Version kernel_7.89
Version kernel_7.91
Version kernel_7.92
Version kernel_7.93
Version kernel_8.04
Version 17.0
Sap
Version 7.22ext
Version 7.53
Version 7.54
Version 7.77
Version 7.85
Version 7.89

References (4)

Source: cna@sap.com
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.