What happened
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.
Affected versions
SAP Extended Passport (EPP) Processing: KRNL64NUC 7.22; 7.22EXT; KRNL64UC 7.22; 7.53; 8.04; WEBDISP 9.16; 9.18; 9.19; 9.20; KERNEL 7.22; 7.54; 7.77; 7.89; 7.93; 9.16 Fixed: See vendor advisory.
Why it matters
Review the vendor advisory and exposure of the affected product to determine operational impact.
Detection & mitigation
- Apply vendor-provided updates or mitigations.
- Review affected product exposure and access logs.
Public PoC references
No public PoC reference has passed the current publication threshold.