cbcvebase.
CVE-2023-40309
published 2023-09-12

CVE-2023-40309: SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a particular user group as well as read, modify or delete restricted data.

Affected

62 ranges· showing 25
VendorProductVersion rangeFixed in
sapcommoncryptolib
sapcontent_server
sapcontent_server
sapcontent_server
sapextended_application_services_and_runtime
saphana_database
saphost_agent
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_java