SAP CommonCryptoLib does not perform necessary boundary checks during pre-authentication parsing of manipulated ASN.1 data over the network. This may result in memory corruption followed by an application crash, hence leading to a high impact on availability. There is no impact on confidentiality or integrity.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap commoncryptolib |
|
| Vendors & Products |
Sap
Sap commoncryptolib |
Tue, 11 Nov 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP CommonCryptoLib does not perform necessary boundary checks during pre-authentication parsing of manipulated ASN.1 data over the network. This may result in memory corruption followed by an application crash, hence leading to a high impact on availability. There is no impact on confidentiality or integrity. | |
| Title | Memory Corruption vulnerability in SAP CommonCryptoLib | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2025-11-11T00:20:44.455Z
Updated: 2025-11-12T20:09:31.961Z
Reserved: 2025-04-16T13:25:34.582Z
Link: CVE-2025-42940
Updated: 2025-11-12T17:30:49.530Z
Status : Awaiting Analysis
Published: 2025-11-11T01:15:39.257
Modified: 2025-11-12T16:19:59.103
Link: CVE-2025-42940
No data.