SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a particular user group as well as read, modify or delete restricted data.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
sap netweaver application server abap kernel 7.53 |
||
sap netweaver application server abap kernel 7.77 |
||
sap web dispatcher 7.53 |
||
sap web dispatcher 7.77 |
||
sap web dispatcher 7.22ext |
||
sap content server 7.53 |
||
sap web dispatcher 7.85 |
||
sap netweaver application server abap kernel 7.22 |
||
sap netweaver application server abap kernel 8.04 |
||
sap netweaver application server abap 7.22ext |
||
sap netweaver application server abap kernel 7.85 |
||
sap web dispatcher 7.89 |
||
sap web dispatcher 7.54 |
||
sap netweaver application server abap kernel 7.89 |
||
sap netweaver application server abap kernel 7.54 |
||
sap netweaver application server abap kernel 7.92 |
||
sap netweaver application server abap kernel 7.93 |
||
sap content server 6.50 |
||
sap content server 7.54 |
||
sap hana database 2.0 |
||
sap host agent 722 |
||
sap extended application services and runtime 1.0 |
||
sap sapssoext 17.0 |
||
sap commoncryptolib 8.0.0 |
||
sap netweaver application server java kernel64nuc 7.22 |
||
sap netweaver application server java kernel64nuc 7.22ext |
||
sap netweaver application server java kernel64uc 7.22 |
||
sap netweaver application server java kernel64uc 7.22ext |
||
sap netweaver application server java kernel64uc 7.53 |
||
sap netweaver application server java kernel64uc 8.04 |
||
sap netweaver application server java kernel 7.22 |
||
sap netweaver application server java kernel 7.53 |
||
sap netweaver application server java kernel 7.54 |
||
sap netweaver application server java kernel 7.77 |
||
sap netweaver application server java kernel 7.85 |
||
sap netweaver application server java kernel 7.89 |
||
sap netweaver application server java kernel 7.91 |
||
sap netweaver application server java kernel 7.92 |
||
sap netweaver application server java kernel 7.93 |
||
sap netweaver application server java kernel 8.04 |
||
sap netweaver application server abap kernel64nuc 7.22 |
||
sap netweaver application server abap kernel64nuc 7.22ext |
||
sap netweaver application server abap kernel64uc 7.22 |
||
sap netweaver application server abap kernel64uc 7.22ext |
||
sap netweaver application server abap kernel64uc 7.53 |
||
sap netweaver application server abap kernel64uc 8.04 |
||
sap netweaver application server abap kernel 7.91 |