CVE-2014-8587: SAP Commoncryptolib
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
SAPCRYPTOLIB before 5.555.38, SAPSECULIB, and CommonCryptoLib before 8.4.30, as used in SAP NetWeaver AS for ABAP and SAP HANA, allows remote attackers to spoof Digital Signature Algorithm (DSA) signatures via unspecified vectors.
Affected products
- SAP Commoncryptolib: up to and including 8.4.29
- SAP Hana: affected versions not specified
- SAP NetWeaver: any version
- SAP Sapcryptolib: up to and including 5.555.37
- SAP Sapseculib: affected versions not specified
Published 2014-11-04. Last modified 2026-06-17.