CVE-2025-42940
BaseFortify
Publication date: 2025-11-11
Last updated on: 2025-11-12
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | commoncryptolib | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in SAP CommonCryptoLib occurs because the software does not perform necessary boundary checks when parsing manipulated ASN.1 data before authentication. This flaw can lead to memory corruption and cause the application to crash.
How can this vulnerability impact me? :
The vulnerability can impact you by causing the affected application to crash, resulting in a loss of availability. There is no impact on confidentiality or integrity.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
This vulnerability does not affect confidentiality or integrity, only availability. Therefore, it is unlikely to directly impact compliance with standards focused on data protection such as GDPR or HIPAA.