VulnerabilityModified
CVE-2016-4407
The DSA algorithm implementation in SAP SAPCRYPTOLIB 5.555.38 does not properly check signatures, which allows remote authenticated users to impersonate arbitrary users via unspecified vectors, aka SAP Security Note 2223008.
MEDIUM 6.5EPSS 0.96%
Does this matter?
Lower severity and a low EPSS score (0.96%). Track it; it rarely justifies an emergency change on its own.
Description
The DSA algorithm implementation in SAP SAPCRYPTOLIB 5.555.38 does not properly check signatures, which allows remote authenticated users to impersonate arbitrary users via unspecified vectors, aka SAP Security Note 2223008.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.96% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- sap/sapcryptolib
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2016/Oct/32Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/93502
- https://www.onapsis.com/research/security-advisories/sap-missing-signature-check-dsa-algorithmPermissions Required
- http://seclists.org/fulldisclosure/2016/Oct/32Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/93502
- https://www.onapsis.com/research/security-advisories/sap-missing-signature-check-dsa-algorithmPermissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.