SAP BusinessObjects BI Platform 4.1, BusinessObjects Edge 4.0, and BusinessObjects XI (BOXI) 3.1 R3 allow remote attackers to cause a denial of service (out-of-bounds read and listener crash) via a crafted GIOP packet, aka SAP Security Note 2001108.
CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:CSap Businessobjects
APPSap4.1Sap Businessobjects Edge
APPSap4.0Sap Businessobjects Xi
APPSap3.1r3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoSMemory
CWE
References
Related vulnerabilities
CVE-2014-9320CRITICAL9.8PL ✓same product
SAP BusinessObjects Edge — kradzież tokenu i privilege escalation do SYSTEM
CVE-2019-0259CRITICAL9.8PL ✓same product
SAP BusinessObjects — nieograniczony upload plików w Visual Difference
CVE-2022-28214HIGH7.8same product
During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authe...
CVE-2015-2074HIGH7.5same product
The File Repository Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to wr...
CVE-2015-2073HIGH7.5same product
The File RepositoRy Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to re...