CVE-2026-44756

Summary

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.

Affected Software

VendorProductVersion RangeStatus
SAP_SESAP Extended Passport (EPP) ProcessingKRNL64NUC 7.22affected
SAP_SESAP Extended Passport (EPP) Processing7.22EXTaffected
SAP_SESAP Extended Passport (EPP) ProcessingKRNL64UC 7.22affected
SAP_SESAP Extended Passport (EPP) Processing7.53affected
SAP_SESAP Extended Passport (EPP) Processing8.04affected
SAP_SESAP Extended Passport (EPP) ProcessingWEBDISP 9.16affected
SAP_SESAP Extended Passport (EPP) Processing9.18affected
SAP_SESAP Extended Passport (EPP) Processing9.19affected
SAP_SESAP Extended Passport (EPP) Processing9.20affected
SAP_SESAP Extended Passport (EPP) ProcessingKERNEL 7.22affected
SAP_SESAP Extended Passport (EPP) Processing7.54affected
SAP_SESAP Extended Passport (EPP) Processing7.77affected
SAP_SESAP Extended Passport (EPP) Processing7.89affected
SAP_SESAP Extended Passport (EPP) Processing7.93affected
SAP_SESAP Extended Passport (EPP) Processing9.16affected

Weaknesses

  • CWE-120: CWE-120: Buffer Copy without Checking Size of Input

References