CVE-2023-40308: SAP Commoncryptolib

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any information.

Affected products

  • SAP Commoncryptolib: version 8.0.0 only
  • SAP Content Server: version 6.50 only; version 7.53 only; version 7.54 only
  • SAP Extended Application Services And Runtime: version 1.0 only
  • SAP Hana Database: version 2.0 only
  • SAP Host Agent: version 722 only
  • SAP NetWeaver Application Server Abap: version 7.22ext only; version kernel_7.22 only; version kernel_7.53 only; version kernel_7.54 only; version kernel_7.77 only; version kernel_7.85 only; …
  • SAP NetWeaver Application Server Java: version kernel_7.22 only; version kernel_7.53 only; version kernel_7.54 only; version kernel_7.77 only; version kernel_7.85 only; version kernel_7.89 only; …
  • SAP Sapssoext: version 17.0 only
  • SAP Web Dispatcher: version 7.22ext only; version 7.53 only; version 7.54 only; version 7.77 only; version 7.85 only; version 7.89 only

Published 2023-09-12. Last modified 2026-06-17.