PT-2015-2432 · Sap · Businessobjects Xi+2
Published
2015-10-15
·
Updated
2015-10-16
·
CVE-2015-7730
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SAP BusinessObjects BI Platform version 4.1
BusinessObjects Edge version 4.0
BusinessObjects XI (BOXI) version 3.1 R3
Description
The issue allows remote attackers to cause a denial of service via a crafted GIOP packet, resulting in an out-of-bounds read and listener crash. This is due to a buffer overflow vulnerability in the affected systems.
Recommendations
For SAP BusinessObjects BI Platform version 4.1, update to a version that addresses the buffer overflow issue to prevent denial of service attacks.
For BusinessObjects Edge version 4.0, apply the necessary patch or update to fix the buffer overflow vulnerability and prevent exploitation.
For BusinessObjects XI (BOXI) version 3.1 R3, consider restricting access to the GIOP packet processing functionality until a patch is available to mitigate the risk of denial of service attacks.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Businessobjects Edge
Businessobjects Xi
Sap Businessobjects Bi Platform