VDB
GCVE-110-NCSC-2026-356
GCVE-110-NCSC-2026-356
Advisory PublishedCVSS 9.1/10
A memory corruption vulnerability in the SAP Extended Passport Protocol (EPP) processing library allows unauthenticated attackers to exploit malformed EPP headers, potentially causing undefined behavior and impacting confidentiality, integrity, and availability.
Weaknesses (CWE)
CWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')CWE-308Use of Single-factor AuthenticationCWE-522Insufficiently Protected CredentialsCWE-807Reliance on Untrusted Inputs in a Security DecisionCWE-862Missing AuthorizationCWE-611Improper Restriction of XML External Entity ReferenceCWE-502Deserialization of Untrusted DataCWE-497Exposure of Sensitive System Information to an Unauthorized Control SphereCWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-918Server-Side Request Forgery (SSRF)CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
Risk Scores
CVSS 3.1
9.1/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| SAP_SE | vers:unknown/* | — | — |
| SAP | vers:unknown/* | — | — |
Browse GCVE Records
495 records in the GCVE database · Updated September 10, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.