SAPCRYPTOLIB before 5.555.38, SAPSECULIB, and CommonCryptoLib before 8.4.30, as used in SAP NetWeaver AS for ABAP and SAP HANA, allows remote attackers to spoof Digital Signature Algorithm (DSA) signatures via unspecified vectors.
2014-11-04T15:55:07.310
2025-04-12T10:46:40.837
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sap | commoncryptolib | ≤ 8.4.29 | Yes |
Application | sap | sapcryptolib | ≤ 5.555.37 | Yes |
Application | sap | sapseculib | - | Yes |
Application | sap | hana | - | Yes |
Application | sap | netweaver | * | Yes |