CVE-2025-42940: Memory Corruption vulnerability in SAP CommonCryptoLib
SAP CommonCryptoLib does not perform necessary boundary checks during pre-authentication parsing of manipulated ASN.1 data over the network. This may result in memory corruption followed by an application crash, hence leading to a high impact on availability. There is no impact on confidentiality or integrity.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42940?
CVE-2025-42940 has a high severity rating due to its potential to cause memory corruption and application crashes.
How do I fix CVE-2025-42940?
To fix CVE-2025-42940, apply the latest security patches and updates provided by SAP for CommonCryptoLib.
What software is affected by CVE-2025-42940?
CVE-2025-42940 affects SAP CommonCryptoLib.
What type of impact does CVE-2025-42940 have on applications?
CVE-2025-42940 can lead to application crashes, significantly affecting availability.
Is CVE-2025-42940 related to data security?
CVE-2025-42940 is primarily an availability issue that results from improper boundary checks in data parsing.