Denial of Service Vulnerability in SAP MaxDB and Netweaver Products
CVE-2015-2278

Currently unrated

Key Information:

Vendor
SAP
Vendor
CVE Published:
2 June 2015

Summary

The vulnerability arises from an issue in the LZH decompression implementation within various SAP products. Attackers can exploit this flaw to trigger a denial of service condition through out-of-bounds read operations, leveraging context-dependent factors. This risk is particularly associated with non-simple code look-ups and can affect the overall functionality of involved systems, including SAP MaxDB and Netweaver application servers.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.