Buffer overflow in CommonCryptoLib - CVE-2023-40308

 

Buffer overflow in CommonCryptoLib - CVE-2023-40308

Published: September 12, 2023


Vulnerability identifier: #VU80691
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-40308
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in SAP CommonCryptoLib. A remote non-authenticated attacker can send specially crafted input to the application that uses the affected library, trigger memory corruption and perform a denial of service (DoS) attack.


Affected software

CommonCryptoLib
SAP SSO EXT
SAP HANA Extended Application Services
SAP HANA
SAP Content Server
SAP NetWeaver AS JAVA
SAP Web Dispatcher Kernel
SAP NetWeaver AS ABAP
SAP Host Agent

How to mitigate CVE-2023-40308

Install updates from vendor's website.


External References

Related Security Bulletins