SAPCRYPTOLIB before 5.555.38, SAPSECULIB, and CommonCryptoLib before 8.4.30, as used in SAP NetWeaver AS for ABAP and SAP HANA, allows remote attackers to spoof Digital Signature Algorithm (DSA) signatures via unspecified vectors.
References
Link | Resource |
---|---|
http://blog.onapsis.com/sap-security-note-2067859-potential-exposure-to-digital-signature-spoofing/ | Broken Link |
http://secunia.com/advisories/57606 | Not Applicable |
http://service.sap.com/sap/support/notes/2067859 | Permissions Required |
https://twitter.com/SAP_Gsupport/status/522401681997570048 | Broken Link |
http://blog.onapsis.com/sap-security-note-2067859-potential-exposure-to-digital-signature-spoofing/ | Broken Link |
http://secunia.com/advisories/57606 | Not Applicable |
http://service.sap.com/sap/support/notes/2067859 | Permissions Required |
https://twitter.com/SAP_Gsupport/status/522401681997570048 | Broken Link |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 02:19
Type | Values Removed | Values Added |
---|---|---|
References | () http://blog.onapsis.com/sap-security-note-2067859-potential-exposure-to-digital-signature-spoofing/ - Broken Link | |
References | () http://secunia.com/advisories/57606 - Not Applicable | |
References | () http://service.sap.com/sap/support/notes/2067859 - Permissions Required | |
References | () https://twitter.com/SAP_Gsupport/status/522401681997570048 - Broken Link |
Information
Published : 2014-11-04 15:55
Updated : 2024-11-21 02:19
NVD link : CVE-2014-8587
Mitre link : CVE-2014-8587
CVE.ORG link : CVE-2014-8587
JSON object : View
Products Affected
sap
- netweaver
- sapcryptolib
- hana
- commoncryptolib
- sapseculib
CWE
CWE-310
Cryptographic Issues