Vulnerability Description
The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to look-ups of non-simple codes, aka SAP Security Note 2124806, 2121661, 2127995, and 2125316.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Gui | - |
| Sap | Maxdb | 7.5 |
| Sap | Netweaver Abap Application Server | - |
| Sap | Netweaver Java Application Server | - |
| Sap | Netweaver Rfc Sdk | - |
| Sap | Rfc Library | All versions |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/131883/SAP-LZC-LZH-Compression-Denial-Of-SeExploit
- http://seclists.org/fulldisclosure/2015/May/50Exploit
- http://seclists.org/fulldisclosure/2015/May/96Exploit
- http://www.coresecurity.com/advisories/sap-lzc-lzh-compression-multiple-vulnerabExploit
- http://www.securityfocus.com/archive/1/535535/100/0/threaded
- http://www.securityfocus.com/bid/74643
- http://packetstormsecurity.com/files/131883/SAP-LZC-LZH-Compression-Denial-Of-SeExploit
- http://seclists.org/fulldisclosure/2015/May/50Exploit
- http://seclists.org/fulldisclosure/2015/May/96Exploit
- http://www.coresecurity.com/advisories/sap-lzc-lzh-compression-multiple-vulnerabExploit
- http://www.securityfocus.com/archive/1/535535/100/0/threaded
- http://www.securityfocus.com/bid/74643
FAQ
What is CVE-2015-2278?
CVE-2015-2278 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver ...
How severe is CVE-2015-2278?
CVE-2015-2278 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-2278?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Gui, Sap Maxdb, Sap Netweaver Abap Application Server, Sap Netweaver Java Application Server, Sap Netweaver Rfc Sdk.