PT-2015-5695 · Sap+1 · Gui+7

Martin Gallo

·

Publicado

2015-06-02

·

Atualizado

2018-10-09

·

CVE-2015-2282

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SAP MaxDB versions 7.5 through 7.6 Netweaver Application Server ABAP (affected versions not specified) Netweaver Application Server Java (affected versions not specified) Netweaver RFC SDK (affected versions not specified) GUI (affected versions not specified) RFC SDK (affected versions not specified) SAPCAR archive tool (affected versions not specified)
Description The issue is related to a stack-based buffer overflow in the LZC decompression implementation, specifically in the CsObjectInt::CsDecomprLZC function. This can be exploited by attackers to cause a denial of service or possibly execute arbitrary code. The exploitation vectors are not specified.
Recommendations For SAP MaxDB versions 7.5 through 7.6, update to a version that includes the fix for the CsObjectInt::CsDecomprLZC function issue. For Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, and SAPCAR archive tool, at the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-2282
SUSE-SU-2016:0805-1
SUSE-SU-2016:0807-1

Produtos afetados

Gui
Sap Netweaver Application Server Abap
Sap Netweaver Application Server Java
Netweaver Rfc Sdk
Rfc Sdk
Sap Maxdb
Sapcar Archive Tool
Suse