Vulnerabilities > CVE-2021-38177 - NULL Pointer Dereference vulnerability in SAP Commoncryptolib 8.4.29/8.5.38

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
sap
CWE-476

Summary

SAP CommonCryptoLib version 8.5.38 or lower is vulnerable to null pointer dereference vulnerability when an unauthenticated attacker sends crafted malicious data in the HTTP requests over the network, this causes the SAP application to crash and has high impact on the availability of the SAP system.

Vulnerable Configurations

Part Description Count
Application
Sap
2

Common Weakness Enumeration (CWE)