Buffer overflow in CommonCryptoLib - CVE-2023-40308
Published: September 12, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in SAP CommonCryptoLib. A remote non-authenticated attacker can send specially crafted input to the application that uses the affected library, trigger memory corruption and perform a denial of service (DoS) attack.
Affected software
SAP SSO EXT
SAP HANA Extended Application Services
SAP HANA
SAP Content Server
SAP NetWeaver AS JAVA
SAP Web Dispatcher Kernel
SAP NetWeaver AS ABAP
SAP Host Agent
How to mitigate CVE-2023-40308
External References
Related Security Bulletins
- Multiple vulnerabilities in SAP CommonCryptoLib
- SAP NetWeaver AS ABAP and JAVA update for CommonCryptoLib
- SAP Web Dispatcher Kernel update for CommonCryptoLib
- SAP Content Server update for CommonCryptoLib
- SAP HANA Database update for CommonCryptoLib
- SAP Host Agent update for CommonCryptoLib
- SAP Extended Application Services and Runtime update for CommonCryptoLib
- SAP SSO EXT update for CommonCryptoLib