CVE-2023-40309
SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a particular user group as well as read, modify or delete restricted data.
Published:Sep 12, 2023
Last Modified:Nov 21, 2024
EPS:Sep 12, 2023
EPSS Score:0.00162
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Sap
Product
Commoncryptolib
Sap
Commoncryptolib
Vendor
Sap
Product
Content Server
Sap
Content Server
Vendor
Sap
Product
Extended Application Services And Runtime
Sap
Extended Application Services And Runtime
Vendor
Sap
Product
Hana Database
Sap
Hana Database
Vendor
Sap
Product
Host Agent
Sap
Host Agent
Vendor
Sap
Product
Netweaver Application Server Abap
Sap
Netweaver Application Server Abap
Vendor
Sap
Product
Netweaver Application Server Java
Sap
Netweaver Application Server Java
Vendor
Sap
Product
Sapssoext
Sap
Sapssoext
Vendor
Sap
Product
Web Dispatcher
Sap
Web Dispatcher
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
