Lucene search

K
nvd[email protected]NVD:CVE-2014-8587
HistoryNov 04, 2014 - 3:55 p.m.

CVE-2014-8587

2014-11-0415:55:07
CWE-310
web.nvd.nist.gov

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.7 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

50.2%

SAPCRYPTOLIB before 5.555.38, SAPSECULIB, and CommonCryptoLib before 8.4.30, as used in SAP NetWeaver AS for ABAP and SAP HANA, allows remote attackers to spoof Digital Signature Algorithm (DSA) signatures via unspecified vectors.

Affected configurations

NVD
Node
sapcommoncryptolibRange8.4.29
OR
sapsapcryptolibRange5.555.37
OR
sapsapseculibMatch-
AND
saphanaMatch-
OR
sapnetweaver

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.7 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

50.2%

Related for NVD:CVE-2014-8587