PT-2021-21986 · Sap · Sap Commoncryptolib
Yvan Genuer
·
Published
2021-09-14
·
Updated
2022-01-28
·
CVE-2021-38177
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
SAP CommonCryptoLib versions 8.5.38 or lower
Description:
The issue is related to a null pointer dereference vulnerability. When an unauthenticated attacker sends crafted malicious data in the HTTP requests over the network, it causes the SAP application to crash. This has a high impact on the availability of the SAP system.
Recommendations:
For SAP CommonCryptoLib versions 8.5.38 or lower, update to a version higher than 8.5.38 to resolve the issue. As a temporary workaround, consider restricting access to the SAP application to minimize the risk of exploitation.
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Commoncryptolib