CVE-2023-40308: Memory Corruption vulnerability in SAP CommonCryptoLib
SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any information.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-40308?
CVE-2023-40308 is a vulnerability in SAP CommonCryptoLib that allows an unauthenticated attacker to cause a memory corruption error, resulting in a crash of the target component.
How does CVE-2023-40308 affect SAP CommonCryptoLib?
CVE-2023-40308 affects SAP CommonCryptoLib by allowing an unauthenticated attacker to craft a request, which when submitted to an open port, causes a memory corruption error.
What is the severity of CVE-2023-40308?
CVE-2023-40308 has a severity value of 7.5, which is classified as high severity.
Which software products are affected by CVE-2023-40308?
SAP CommonCryptoLib, SAP Content Server, Sap Extended Application Services And Runtime, SAP Hana Database, SAP Host Agent, and SAP NetWeaver Application Server ABAP and Java are among the software products affected by CVE-2023-40308.
How can I mitigate CVE-2023-40308?
Mitigate CVE-2023-40308 by applying the necessary patches or updates provided by SAP and following the recommended security practices.