SAP CommonCryptoLib是德国思爱普(SAP)公司的一个密码库。 SAP CommonCryptoLib 存在代码问题漏洞,该漏洞源于允许未经身份验证的攻击者制作请求,该请求在提交到开放端口时会导致库中出现内存损坏错误,进而导致目标组件崩溃,使其不可用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP CommonCryptoLib | 8 | - |
|
| SAP_SE | SAP NetWeaver AS ABAP, SAP NetWeaver AS Java and ABAP Platform of S/4HANA on-premise | KERNEL 7.22 | - |
|
| SAP_SE | SAP Web Dispatcher | 7.22EXT | - |
|
| SAP_SE | SAP Content Server | 6.50 | - |
|
| SAP_SE | SAP HANA Database | 2.00 | - |
|
| SAP_SE | SAP Host Agent | 722 | - |
|
| SAP_SE | SAP Extended Application Services and Runtime (XSA) | SAP_EXTENDED_APP_SERVICES 1 | - |
|
| SAP_SE | SAPSSOEXT | 17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-40622 | 9.9 CRITICAL | Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform |
| CVE-2023-40309 | 9.8 CRITICAL | Missing Authorization check in SAP CommonCryptoLib |
| CVE-2023-42472 | 8.7 HIGH | Insufficient File type validation in SAP BusinessObjects Business Intelligence Platform (W |
| CVE-2023-40621 | 6.3 MEDIUM | Code Injection vulnerability in SAP PowerDesigner Client |
| CVE-2023-40623 | 6.2 MEDIUM | Arbitrary File Delete via Directory Junction in SAP BusinessObjects Suite(installer) |
| CVE-2023-40624 | 5.5 MEDIUM | Code Injection vulnerability in SAP NetWeaver AS ABAP (applications based on Unified Rende |
| CVE-2023-40625 | 5.4 MEDIUM | Missing Authorization check in SAP Manage Purchase Contracts App |
| CVE-2023-41367 | 5.3 MEDIUM | Missing Authentication check in SAP NetWeaver (Guided Procedures) |
| CVE-2023-37489 | 5.3 MEDIUM | Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform |
| CVE-2023-41369 | 3.5 LOW | External Entity Loop vulnerability in SAP S/4HANA (Create Single Payment application) |
| CVE-2023-41368 | 2.7 LOW | Insecure Direct Object Reference (IDOR) vulnerability in S4 HANA (Manage checkbook apps) |
No comments yet