MEDIUM · 5.0

CVE-2015-2278

The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver ...

Vulnerability Description

The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to look-ups of non-simple codes, aka SAP Security Note 2124806, 2121661, 2127995, and 2125316.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
SapGui-
SapMaxdb7.5
SapNetweaver Abap Application Server-
SapNetweaver Java Application Server-
SapNetweaver Rfc Sdk-
SapRfc LibraryAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-2278?

CVE-2015-2278 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver ...

How severe is CVE-2015-2278?

CVE-2015-2278 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-2278?

Check the references section above for vendor advisories and patch information. Affected products include: Sap Gui, Sap Maxdb, Sap Netweaver Abap Application Server, Sap Netweaver Java Application Server, Sap Netweaver Rfc Sdk.