CVE-2016-4407

MEDIUM

SAP SAPCRYPTOLIB <5.555.38 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The DSA algorithm implementation in SAP SAPCRYPTOLIB 5.555.38 does not properly check signatures, which allows remote authenticated users to impersonate arbitrary users via unspecified vectors, aka SAP Security Note 2223008.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93502
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2016/Oct/32

Scores

CVSS v3 6.5
EPSS 0.0016
EPSS Percentile 36.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-284
Status published
Products (1)
sap/sapcryptolib 5.555.38
Published Oct 13, 2016
Tracked Since Feb 18, 2026