HIGH · 7.5

CVE-2015-2282

Stack-based buffer overflow in the LZC decompression implementation (CsObjectInt::CsDecomprLZC function in vpa106cslzc.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Appli...

Vulnerability Description

Stack-based buffer overflow in the LZC decompression implementation (CsObjectInt::CsDecomprLZC function in vpa106cslzc.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, aka SAP Security Note 2124806, 2121661, 2127995, and 2125316.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
SapGui-
SapMaxdb7.5
SapNetweaver Abap Application Server-
SapNetweaver Java Application Server-
SapNetweaver Rfc Sdk-
SapRfc LibraryAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-2282?

CVE-2015-2282 is a vulnerability with a CVSS score of 7.5 (HIGH). Stack-based buffer overflow in the LZC decompression implementation (CsObjectInt::CsDecomprLZC function in vpa106cslzc.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Appli...

How severe is CVE-2015-2282?

CVE-2015-2282 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-2282?

Check the references section above for vendor advisories and patch information. Affected products include: Sap Gui, Sap Maxdb, Sap Netweaver Abap Application Server, Sap Netweaver Java Application Server, Sap Netweaver Rfc Sdk.