VDB

GCVE-110-NCSC-2026-356

GCVE-110-NCSC-2026-356
Advisory PublishedCVSS 9.1/10
Vulnetix · Advisory published September 9, 2026
A memory corruption vulnerability in the SAP Extended Passport Protocol (EPP) processing library allows unauthenticated attackers to exploit malformed EPP headers, potentially causing undefined behavior and impacting confidentiality, integrity, and availability.

Weaknesses (CWE)

CWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')CWE-308Use of Single-factor AuthenticationCWE-522Insufficiently Protected CredentialsCWE-807Reliance on Untrusted Inputs in a Security DecisionCWE-862Missing AuthorizationCWE-611Improper Restriction of XML External Entity ReferenceCWE-502Deserialization of Untrusted DataCWE-497Exposure of Sensitive System Information to an Unauthorized Control SphereCWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-918Server-Side Request Forgery (SSRF)CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Risk Scores

CVSS 3.1
9.1/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersionsPlatforms
SAP_SEvers:unknown/*
SAPvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

495 records in the GCVE database · Updated September 10, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›