PT-2023-6627 · Sap · Sap Commoncryptolib

Published

2023-09-11

·

Updated

2024-09-26

·

CVE-2023-40308

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SAP CommonCryptoLib (affected versions not specified)
Description The issue allows an unauthenticated attacker to craft a request, which when submitted to an open port, causes a memory corruption error in a library. This error in turn causes the target component to crash, making it unavailable. There is no ability to view or modify any information. The vulnerability is related to pointer dereference errors.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2023-07394
CVE-2023-40308

Affected Products

Sap Commoncryptolib