9.8

CVE-2023-40309

SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a particular user group as well as read, modify or delete restricted data.

Data is provided by the National Vulnerability Database (NVD)
SAPCommoncryptolib Version8.0.0
SAPContent Server Version6.50
SAPContent Server Version7.53
SAPContent Server Version7.54
SAPHana Database Version2.0
SAPHost Agent Version722
SAPNetweaver Application Server Abap Versionkernel_7.22
SAPNetweaver Application Server Abap Versionkernel_7.53
SAPNetweaver Application Server Abap Versionkernel_7.54
SAPNetweaver Application Server Abap Versionkernel_7.77
SAPNetweaver Application Server Abap Versionkernel_7.85
SAPNetweaver Application Server Abap Versionkernel_7.89
SAPNetweaver Application Server Abap Versionkernel_7.91
SAPNetweaver Application Server Abap Versionkernel_7.92
SAPNetweaver Application Server Abap Versionkernel_7.93
SAPNetweaver Application Server Abap Versionkernel_8.04
SAPNetweaver Application Server Abap Versionkernel64nuc_7.22
SAPNetweaver Application Server Abap Versionkernel64nuc_7.22ext
SAPNetweaver Application Server Abap Versionkernel64uc_7.22
SAPNetweaver Application Server Abap Versionkernel64uc_7.22ext
SAPNetweaver Application Server Abap Versionkernel64uc_7.53
SAPNetweaver Application Server Abap Versionkernel64uc_8.04
SAPNetweaver Application Server Java Versionkernel_7.22
SAPNetweaver Application Server Java Versionkernel_7.53
SAPNetweaver Application Server Java Versionkernel_7.54
SAPNetweaver Application Server Java Versionkernel_7.77
SAPNetweaver Application Server Java Versionkernel_7.85
SAPNetweaver Application Server Java Versionkernel_7.89
SAPNetweaver Application Server Java Versionkernel_7.91
SAPNetweaver Application Server Java Versionkernel_7.92
SAPNetweaver Application Server Java Versionkernel_7.93
SAPNetweaver Application Server Java Versionkernel_8.04
SAPNetweaver Application Server Java Versionkernel64nuc_7.22
SAPNetweaver Application Server Java Versionkernel64nuc_7.22ext
SAPNetweaver Application Server Java Versionkernel64uc_7.22
SAPNetweaver Application Server Java Versionkernel64uc_7.22ext
SAPNetweaver Application Server Java Versionkernel64uc_7.53
SAPNetweaver Application Server Java Versionkernel64uc_8.04
SAPSapssoext Version17.0
SAPWeb Dispatcher Version7.22ext
SAPWeb Dispatcher Version7.53
SAPWeb Dispatcher Version7.54
SAPWeb Dispatcher Version7.77
SAPWeb Dispatcher Version7.85
SAPWeb Dispatcher Version7.89
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.16% 0.38
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cna@sap.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.