Improper Authentication in CommonCryptoLib - CVE-2023-40309

 

Improper Authentication in CommonCryptoLib - CVE-2023-40309

Published: September 12, 2023


Vulnerability identifier: #VU80681
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-40309
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in SAP CommonCryptoLib. A remote attacker can bypass authentication process and gain unauthorized access to the application.


Affected software

CommonCryptoLib
SAP SSO EXT
SAP HANA Extended Application Services
SAP HANA
SAP Content Server
SAP NetWeaver AS JAVA
SAP Web Dispatcher Kernel
SAP NetWeaver AS ABAP
SAP Host Agent

How to mitigate CVE-2023-40309

Install updates from vendor's website.


External References

Related Security Bulletins