ZeroHour

CVE-2023-40308

CVSS 3.1
7.5 high
EPSS
<1%p48
Published
()
Modified
Description

SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any information.

Vendors
sap
Products
commoncryptolib, content server, extended application services and runtime, hana database, host agent, netweaver application server abap, netweaver application server java, sapssoext, web dispatcher
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.