SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any information.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://me.sap.com/notes/3327896 | vendor advisory permissions required |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | vendor advisory |