CVE-2023-40309: SAP Commoncryptolib

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a particular user group as well as read, modify or delete restricted data.

Affected products

  • SAP Commoncryptolib: version 8.0.0 only
  • SAP Content Server: version 6.50 only; version 7.53 only; version 7.54 only
  • SAP Extended Application Services And Runtime: version 1.0 only
  • SAP Hana Database: version 2.0 only
  • SAP Host Agent: version 722 only
  • SAP NetWeaver Application Server Abap: version 7.22ext only; version kernel_7.22 only; version kernel_7.53 only; version kernel_7.54 only; version kernel_7.77 only; version kernel_7.85 only; …
  • SAP NetWeaver Application Server Java: version kernel_7.22 only; version kernel_7.53 only; version kernel_7.54 only; version kernel_7.77 only; version kernel_7.85 only; version kernel_7.89 only; …
  • SAP Sapssoext: version 17.0 only
  • SAP Web Dispatcher: version 7.22ext only; version 7.53 only; version 7.54 only; version 7.77 only; version 7.85 only; version 7.89 only

Published 2023-09-12. Last modified 2026-06-17.