Lucene search

K
cvelistSapCVELIST:CVE-2021-38177
HistorySep 14, 2021 - 11:24 a.m.

CVE-2021-38177

2021-09-1411:24:27
sap
www.cve.org
2
sap
commoncryptolib
null pointer dereference
http requests
network
attacker
crafted malicious data
crash
availability
high impact

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.025

Percentile

90.3%

SAP CommonCryptoLib version 8.5.38 or lower is vulnerable to null pointer dereference vulnerability when an unauthenticated attacker sends crafted malicious data in the HTTP requests over the network, this causes the SAP application to crash and has high impact on the availability of the SAP system.

CNA Affected

[
  {
    "product": "SAP CommonCryptoLib",
    "vendor": "SAP SE",
    "versions": [
      {
        "status": "affected",
        "version": "< 8.5.38 or lower"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.025

Percentile

90.3%

Related for CVELIST:CVE-2021-38177