CVE-2021-38177
SAP CommonCryptoLib version 8.5.38 or lower is vulnerable to null pointer dereference vulnerability when an unauthenticated attacker sends crafted malicious data in the HTTP requests over the network, this causes the SAP application to crash and has…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.22%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SAP CommonCryptoLib version 8.5.38 or lower is vulnerable to null pointer dereference vulnerability when an unauthenticated attacker sends crafted malicious data in the HTTP requests over the network, this causes the SAP application to crash and has high impact on the availability of the SAP system.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 3.22% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- sap/commoncryptolib
- Source
- cna@sap.com
References
- http://packetstormsecurity.com/files/165749/SAP-CommonCryptoLib-Null-Pointer-Dereference.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2022/Jan/74Mailing List, Mitigation, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/3051787Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405Vendor Advisory
- http://packetstormsecurity.com/files/165749/SAP-CommonCryptoLib-Null-Pointer-Dereference.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2022/Jan/74Mailing List, Mitigation, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/3051787Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.