High severity7.5NVD Advisory· Published Sep 14, 2021· Updated Jun 17, 2026
CVE-2021-38177
CVE-2021-38177
Description
SAP CommonCryptoLib version 8.5.38 or lower is vulnerable to null pointer dereference vulnerability when an unauthenticated attacker sends crafted malicious data in the HTTP requests over the network, this causes the SAP application to crash and has high impact on the availability of the SAP system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- SAP SE/SAP CommonCryptoLibv5Range: < 8.5.38 or lower
<=8.5.38+ 1 more
- (no CPE)range: <=8.5.38
- cpe:2.3:a:sap:commoncryptolib:*:*:*:*:*:*:*:*range: <=8.5.38
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/165749/SAP-CommonCryptoLib-Null-Pointer-Dereference.htmlnvdThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2022/Jan/74nvdMailing ListMitigationThird Party Advisory
- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.