PT-2015-2432 · Sap · Businessobjects Xi+2

Published

2015-10-15

·

Updated

2015-10-16

·

CVE-2015-7730

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SAP BusinessObjects BI Platform version 4.1 BusinessObjects Edge version 4.0 BusinessObjects XI (BOXI) version 3.1 R3
Description The issue allows remote attackers to cause a denial of service via a crafted GIOP packet, resulting in an out-of-bounds read and listener crash. This is due to a buffer overflow vulnerability in the affected systems.
Recommendations For SAP BusinessObjects BI Platform version 4.1, update to a version that addresses the buffer overflow issue to prevent denial of service attacks. For BusinessObjects Edge version 4.0, apply the necessary patch or update to fix the buffer overflow vulnerability and prevent exploitation. For BusinessObjects XI (BOXI) version 3.1 R3, consider restricting access to the GIOP packet processing functionality until a patch is available to mitigate the risk of denial of service attacks.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11797
CVE-2015-7730

Affected Products

Sap Businessobjects Edge
Businessobjects Xi
Sap Businessobjects Bi Platform