CVE-2021-38177

SAP CommonCryptoLib version 8.5.38 or lower is vulnerable to null pointer dereference vulnerability when an unauthenticated attacker sends crafted malicious data in the HTTP requests over the network, this causes the SAP application to crash and has high impact on the availability of the SAP system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sap:commoncryptolib:*:*:*:*:*:*:*:*

History

28 Jan 2022, 21:01

Type Values Removed Values Added
References (FULLDISC) http://seclists.org/fulldisclosure/2022/Jan/74 - (FULLDISC) http://seclists.org/fulldisclosure/2022/Jan/74 - Mailing List, Mitigation, Third Party Advisory
References (MISC) http://packetstormsecurity.com/files/165749/SAP-CommonCryptoLib-Null-Pointer-Dereference.html - (MISC) http://packetstormsecurity.com/files/165749/SAP-CommonCryptoLib-Null-Pointer-Dereference.html - Third Party Advisory, VDB Entry

27 Jan 2022, 17:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/165749/SAP-CommonCryptoLib-Null-Pointer-Dereference.html -

26 Jan 2022, 19:15

Type Values Removed Values Added
References
  • (FULLDISC) http://seclists.org/fulldisclosure/2022/Jan/74 -

24 Sep 2021, 19:59

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
CWE CWE-476
CPE cpe:2.3:a:sap:commoncryptolib:*:*:*:*:*:*:*:*
References (MISC) https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405 - (MISC) https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405 - Vendor Advisory
References (MISC) https://launchpad.support.sap.com/#/notes/3051787 - (MISC) https://launchpad.support.sap.com/#/notes/3051787 - Permissions Required

14 Sep 2021, 13:01

Type Values Removed Values Added
New CVE

Information

Published : 2021-09-14 12:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-38177

Mitre link : CVE-2021-38177

CVE.ORG link : CVE-2021-38177


JSON object : View

Products Affected

sap

  • commoncryptolib
CWE
CWE-476

NULL Pointer Dereference