9.8
CVSSv3

CVE-2023-40309

Published: 12/09/2023 Updated: 15/09/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a particular user group as well as read, modify or delete restricted data.

Vulnerable Product Search on Vulmon Subscribe to Product

sap netweaver application server abap kernel_7.53

sap netweaver application server abap kernel_7.77

sap web dispatcher 7.53

sap web dispatcher 7.77

sap web dispatcher 7.22ext

sap content server 7.53

sap web dispatcher 7.85

sap netweaver application server abap kernel_7.22

sap netweaver application server abap kernel_8.04

sap netweaver application server abap 7.22ext

sap netweaver application server abap kernel_7.85

sap web dispatcher 7.89

sap web dispatcher 7.54

sap netweaver application server abap kernel_7.89

sap netweaver application server abap kernel_7.54

sap netweaver application server abap kernel_7.92

sap netweaver application server abap kernel_7.93

sap content server 6.50

sap content server 7.54

sap hana database 2.0

sap host agent 722

sap extended application services and runtime 1.0

sap sapssoext 17.0

sap commoncryptolib 8.0.0

sap netweaver application server java kernel64nuc_7.22

sap netweaver application server java kernel64nuc_7.22ext

sap netweaver application server java kernel64uc_7.22

sap netweaver application server java kernel64uc_7.22ext

sap netweaver application server java kernel64uc_7.53

sap netweaver application server java kernel64uc_8.04

sap netweaver application server java kernel_7.22

sap netweaver application server java kernel_7.53

sap netweaver application server java kernel_7.54

sap netweaver application server java kernel_7.77

sap netweaver application server java kernel_7.85

sap netweaver application server java kernel_7.89

sap netweaver application server java kernel_7.91

sap netweaver application server java kernel_7.92

sap netweaver application server java kernel_7.93

sap netweaver application server java kernel_8.04

sap netweaver application server abap kernel64nuc_7.22

sap netweaver application server abap kernel64nuc_7.22ext

sap netweaver application server abap kernel64uc_7.22

sap netweaver application server abap kernel64uc_7.22ext

sap netweaver application server abap kernel64uc_7.53

sap netweaver application server abap kernel64uc_8.04

sap netweaver application server abap kernel_7.91