CVE-2014-8587: High severity SAP CommonCryptoLib vulnerability
SAPCRYPTOLIB before 5.555.38, SAPSECULIB, and CommonCryptoLib before 8.4.30, as used in SAP NetWeaver AS for ABAP and SAP HANA, allows remote attackers to spoof Digital Signature Algorithm (DSA) signatures via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8587?
CVE-2014-8587 is considered a high severity vulnerability due to its potential for remote exploitation and impact on digital signature integrity.
How do I fix CVE-2014-8587?
To fix CVE-2014-8587, update SAPCRYPTOLIB, SAPSECULIB, and CommonCryptoLib to versions 5.555.38 or 8.4.30 or later.
What impact does CVE-2014-8587 have?
CVE-2014-8587 allows remote attackers to spoof Digital Signature Algorithm (DSA) signatures, compromising the authenticity of signed data.
Which SAP products are affected by CVE-2014-8587?
CVE-2014-8587 affects SAP NetWeaver AS for ABAP, SAP HANA, SAPCRYPTOLIB versions lower than 5.555.38, SAPSECULIB, and CommonCryptoLib versions lower than 8.4.30.
Is CVE-2014-8587 being actively exploited?
While there have been no confirmed reports of active exploitation for CVE-2014-8587, the nature of the vulnerability warrants immediate remediation.