PT-2016-5941 · Sap · Sapcryptolib
Fernando Russ
+2
·
Published
2016-10-13
·
Updated
2016-11-28
·
CVE-2016-4407
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SAP SAPCRYPTOLIB version 5.555.38
Description
The issue concerns the DSA algorithm implementation, which does not properly check signatures. This allows remote authenticated users to impersonate arbitrary users via unspecified vectors.
Recommendations
For SAP SAPCRYPTOLIB version 5.555.38, update to a version that properly checks signatures to prevent impersonation.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sapcryptolib