CVE-2023-40308
SAP HANA vulnerability analysis and mitigation

Overview

SAP CommonCryptoLib vulnerability (CVE-2023-40308) was disclosed on September 11, 2023. This vulnerability allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library that leads to component crash and unavailability. The vulnerability affects multiple SAP products including SAP CommonCryptoLib 8.0.0, NetWeaver AS ABAP, NetWeaver AS Java, ABAP Platform of S/4HANA on-premise, Web Dispatcher, Content Server, HANA Database, Host Agent, and Extended Application Services and Runtime (SecurityWeek, NVD).

Technical details

The vulnerability is classified as a memory corruption issue with a CVSS v3.1 Base Score of 7.5 (High). The attack vector is Network (AV:N), with Low attack complexity (AC:L), requiring No privileges (PR:N) and No user interaction (UI:N). The scope is Unchanged (S:U), with No impact on confidentiality (C:N) or integrity (I:N), but High impact on availability (A:H). The vulnerability is identified as CWE-787 (Out-of-bounds Write) (NVD).

Impact

When exploited, the vulnerability results in a denial of service condition by causing the target component to crash, making it unavailable. Importantly, there is no ability for attackers to view or modify any information through this vulnerability (NVD, CyberSecurityNews).

Mitigation and workarounds

SAP has released patches to address this vulnerability as part of their September 2023 Security Patch Day. The patches for CVE-2023-40309 automatically address this issue as well. Organizations are advised to apply the security updates to affected systems (SecurityWeek).

Additional resources


SourceThis report was generated using AI

Related SAP HANA vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-40309CRITICAL9.8
  • SAP HANASAP HANA
  • cpe:2.3:a:sap:hana_database
NoYesSep 12, 2023
CVE-2021-21484CRITICAL9.8
  • SAP HANASAP HANA
  • cpe:2.3:a:sap:hana
NoYesMar 09, 2021
CVE-2023-40308HIGH7.5
  • SAP HANASAP HANA
  • cpe:2.3:a:sap:hana_database
NoYesSep 12, 2023
CVE-2021-21474MEDIUM6.5
  • SAP HANASAP HANA
  • cpe:2.3:a:sap:hana_database
NoYesFeb 09, 2021
CVE-2020-26834MEDIUM5.4
  • SAP HANASAP HANA
  • cpe:2.3:a:sap:hana_database
NoYesDec 09, 2020

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management