CVE-2009-4988: Buffer Overflow
Published Aug 25, 2010
·Updated
Stack-based buffer overflow in NTNamingService.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote attackers to execute arbitrary code via a long GIOP request to TCP port 30000.
Affected Software
2 affected components
SAP Business One 2005-a=6.80.320
SAP Business One 2005-a=6.80.123
Event History
Aug 25, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-4988?
CVE-2009-4988 is classified as critical due to its potential for remote code execution.
2
How do I fix CVE-2009-4988?
To mitigate CVE-2009-4988, it is recommended to apply the latest security patches provided by SAP.
3
Which versions are affected by CVE-2009-4988?
CVE-2009-4988 affects SAP Business One versions 6.80.123 and 6.80.320.
4
What type of vulnerability is CVE-2009-4988?
CVE-2009-4988 is a stack-based buffer overflow vulnerability.
5
Can CVE-2009-4988 be exploited remotely?
Yes, CVE-2009-4988 can be exploited remotely via a specially crafted GIOP request.