First published: Mon Oct 18 2010(Updated: )
Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 does not limit the number of CUIDs that may be requested, which allows remote authenticated users to cause a denial of service via a large numCuids value in a GenerateCuids SOAPAction to the dswsbobje/services/biplatform URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects | =3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3980 is classified as a medium severity vulnerability due to its potential to cause a denial of service.
To mitigate CVE-2010-3980, limit the number of CUIDs that can be requested in the GenerateCuids SOAPAction.
CVE-2010-3980 affects remote authenticated users of SAP BusinessObjects Enterprise XI 3.2.
CVE-2010-3980 can be exploited to perform a denial of service attack by overloading the system with large numCuids requests.
The impact of CVE-2010-3980 on SAP BusinessObjects is the potential disruption of service due to excessive resource consumption.