CVE-2023-40308: SAP Commoncryptolib
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any information.
Affected products
- SAP Commoncryptolib: version 8.0.0 only
- SAP Content Server: version 6.50 only; version 7.53 only; version 7.54 only
- SAP Extended Application Services And Runtime: version 1.0 only
- SAP Hana Database: version 2.0 only
- SAP Host Agent: version 722 only
- SAP NetWeaver Application Server Abap: version 7.22ext only; version kernel_7.22 only; version kernel_7.53 only; version kernel_7.54 only; version kernel_7.77 only; version kernel_7.85 only; …
- SAP NetWeaver Application Server Java: version kernel_7.22 only; version kernel_7.53 only; version kernel_7.54 only; version kernel_7.77 only; version kernel_7.85 only; version kernel_7.89 only; …
- SAP Sapssoext: version 17.0 only
- SAP Web Dispatcher: version 7.22ext only; version 7.53 only; version 7.54 only; version 7.77 only; version 7.85 only; version 7.89 only
Published 2023-09-12. Last modified 2026-06-17.