CVE-2021-38177 is a null pointer dereference vulnerability in SAP CommonCryptoLib versions 8.5.38 and lower. An unauthenticated attacker can exploit this by sending crafted HTTP requests, leading to a denial-of-service condition and high impact on system availability. With a CVSS score of 7.5 (High), it requires no user interaction or privileges, making it easily exploitable over the network. While there are no public exploits or active exploitation observed, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.5.38CPE matchmatch criteria | cpe:2.3:a:sap:commoncryptolib:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.