Vulnerability Description
Stack-based buffer overflow in the LZC decompression implementation (CsObjectInt::CsDecomprLZC function in vpa106cslzc.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, aka SAP Security Note 2124806, 2121661, 2127995, and 2125316.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Gui | - |
| Sap | Maxdb | 7.5 |
| Sap | Netweaver Abap Application Server | - |
| Sap | Netweaver Java Application Server | - |
| Sap | Netweaver Rfc Sdk | - |
| Sap | Rfc Library | All versions |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/131883/SAP-LZC-LZH-Compression-Denial-Of-SeExploit
- http://seclists.org/fulldisclosure/2015/May/50Exploit
- http://seclists.org/fulldisclosure/2015/May/96Exploit
- http://www.coresecurity.com/advisories/sap-lzc-lzh-compression-multiple-vulnerabExploit
- http://www.securityfocus.com/archive/1/535535/100/0/threaded
- http://www.securityfocus.com/bid/74643
- http://packetstormsecurity.com/files/131883/SAP-LZC-LZH-Compression-Denial-Of-SeExploit
- http://seclists.org/fulldisclosure/2015/May/50Exploit
- http://seclists.org/fulldisclosure/2015/May/96Exploit
- http://www.coresecurity.com/advisories/sap-lzc-lzh-compression-multiple-vulnerabExploit
- http://www.securityfocus.com/archive/1/535535/100/0/threaded
- http://www.securityfocus.com/bid/74643
FAQ
What is CVE-2015-2282?
CVE-2015-2282 is a vulnerability with a CVSS score of 7.5 (HIGH). Stack-based buffer overflow in the LZC decompression implementation (CsObjectInt::CsDecomprLZC function in vpa106cslzc.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Appli...
How severe is CVE-2015-2282?
CVE-2015-2282 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-2282?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Gui, Sap Maxdb, Sap Netweaver Abap Application Server, Sap Netweaver Java Application Server, Sap Netweaver Rfc Sdk.