Lucene search

K
cve[email protected]CVE-2023-40308
HistorySep 12, 2023 - 2:15 a.m.

CVE-2023-40308

2023-09-1202:15:12
CWE-476
web.nvd.nist.gov
30
cve-2023-40308
sap
commoncryptolib
memory corruption
vulnerability
nvd

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

20.7%

SAP CommonCryptoLibย allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any information.

Affected configurations

NVD
Node
sapcommoncryptolibMatch8.0.0
OR
sapcontent_serverMatch6.50
OR
sapcontent_serverMatch7.53
OR
sapcontent_serverMatch7.54
OR
sapextended_application_services_and_runtimeMatch1.0
OR
saphana_databaseMatch2.0
OR
saphost_agentMatch722
OR
sapnetweaver_application_server_abapMatch7.22ext
OR
sapnetweaver_application_server_abapMatchkernel_7.22
OR
sapnetweaver_application_server_abapMatchkernel_7.53
OR
sapnetweaver_application_server_abapMatchkernel_7.54
OR
sapnetweaver_application_server_abapMatchkernel_7.77
OR
sapnetweaver_application_server_abapMatchkernel_7.85
OR
sapnetweaver_application_server_abapMatchkernel_7.89
OR
sapnetweaver_application_server_abapMatchkernel_7.91
OR
sapnetweaver_application_server_abapMatchkernel_7.92
OR
sapnetweaver_application_server_abapMatchkernel_7.93
OR
sapnetweaver_application_server_abapMatchkernel_8.04
OR
sapnetweaver_application_server_abapMatchkernel64nuc_7.22
OR
sapnetweaver_application_server_abapMatchkernel64nuc_7.22ext
OR
sapnetweaver_application_server_abapMatchkernel64uc_7.22
OR
sapnetweaver_application_server_abapMatchkernel64uc_7.22ext
OR
sapnetweaver_application_server_abapMatchkernel64uc_7.53
OR
sapnetweaver_application_server_abapMatchkernel64uc_8.04
OR
sapnetweaver_application_server_javaMatchkernel_7.22
OR
sapnetweaver_application_server_javaMatchkernel_7.53
OR
sapnetweaver_application_server_javaMatchkernel_7.54
OR
sapnetweaver_application_server_javaMatchkernel_7.77
OR
sapnetweaver_application_server_javaMatchkernel_7.85
OR
sapnetweaver_application_server_javaMatchkernel_7.89
OR
sapnetweaver_application_server_javaMatchkernel_7.91
OR
sapnetweaver_application_server_javaMatchkernel_7.92
OR
sapnetweaver_application_server_javaMatchkernel_7.93
OR
sapnetweaver_application_server_javaMatchkernel_8.04
OR
sapnetweaver_application_server_javaMatchkernel64nuc_7.22
OR
sapnetweaver_application_server_javaMatchkernel64nuc_7.22ext
OR
sapnetweaver_application_server_javaMatchkernel64uc_7.22
OR
sapnetweaver_application_server_javaMatchkernel64uc_7.22ext
OR
sapnetweaver_application_server_javaMatchkernel64uc_7.53
OR
sapnetweaver_application_server_javaMatchkernel64uc_8.04
OR
sapsapssoextMatch17.0
OR
sapweb_dispatcherMatch7.22ext
OR
sapweb_dispatcherMatch7.53
OR
sapweb_dispatcherMatch7.54
OR
sapweb_dispatcherMatch7.77
OR
sapweb_dispatcherMatch7.85
OR
sapweb_dispatcherMatch7.89

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "SAP CommonCryptoLib",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "8"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "packageName": "KERNEL",
    "product": "SAP NetWeaver AS ABAP, SAP NetWeaver AS Java and ABAP Platform of S/4HANA on-premise",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "KERNEL 7.22"
      },
      {
        "status": "affected",
        "version": "KERNEL 7.53"
      },
      {
        "status": "affected",
        "version": "KERNEL 7.54"
      },
      {
        "status": "affected",
        "version": "KERNEL 7.77"
      },
      {
        "status": "affected",
        "version": "KERNEL 7.85"
      },
      {
        "status": "affected",
        "version": "KERNEL 7.89"
      },
      {
        "status": "affected",
        "version": "KERNEL 7.91"
      },
      {
        "status": "affected",
        "version": "KERNEL 7.92"
      },
      {
        "status": "affected",
        "version": "KERNEL 7.93"
      },
      {
        "status": "affected",
        "version": "KERNEL 8.04"
      },
      {
        "status": "affected",
        "version": "KERNEL64UC 7.22"
      },
      {
        "status": "affected",
        "version": "KERNEL64UC 7.22EXT"
      },
      {
        "status": "affected",
        "version": "KERNEL64UC 7.53"
      },
      {
        "status": "affected",
        "version": "KERNEL64UC 8.04"
      },
      {
        "status": "affected",
        "version": "KERNEL64NUC 7.22"
      },
      {
        "status": "affected",
        "version": "KERNEL64NUC 7.22EXT"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "SAP Web Dispatcher",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "7.22EXT"
      },
      {
        "status": "affected",
        "version": "7.53"
      },
      {
        "status": "affected",
        "version": "7.54"
      },
      {
        "status": "affected",
        "version": "7.77"
      },
      {
        "status": "affected",
        "version": "7.85"
      },
      {
        "status": "affected",
        "version": "7.89"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "SAP Content Server",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "6.50"
      },
      {
        "status": "affected",
        "version": "7.53"
      },
      {
        "status": "affected",
        "version": "7.54"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "SAP HANA Database",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "2.00"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "SAP Host Agent",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "722"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "SAP Extended Application Services and Runtime (XSA)",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "SAP_EXTENDED_APP_SERVICES 1"
      },
      {
        "status": "affected",
        "version": "XS_ADVANCED_RUNTIME 1.00"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "SAPSSOEXT",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "17"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

20.7%

Related for CVE-2023-40308