Impact
The vulnerability is a memory corruption flaw in the Extended Passport Protocol processing library that allows an unauthenticated attacker to send a crafted network request with a malformed EPP header. Because the library does not properly validate the header, the flaw leads to undefined behavior and can terminate the application. The impact is high, potentially compromising confidentiality, integrity and availability of the SAP application as the crash may allow malicious disclosure or manipulation of data. The weakness is a buffer overrun (CWE‑120).
Affected Systems
The affected product is SAP Extended Passport (EPP) Processing from SAP. No specific version number was supplied, so all installations of the EPP Processing library are potentially vulnerable. Older or unpatched deployments must be reviewed and upgraded.
Risk and Exploitability
The CVSS score is 10, indicating maximum severity. The EPSS score is not available, but the flaw can be triggered remotely via the network, and the attacker requires no authentication. Since the vulnerability is listed in SAP’s security note and is not currently in the CISA KEV catalog, exploitation may still occur in the wild if the library is not patched. The likely attack vector is a remote request to the EPP endpoint, and exploitation results in abnormal program termination that could be leveraged for denial of service or, if combined with other flaws, for privilege escalation.
OpenCVE Enrichment