CVE-2014-9387: Critical severity sap businessobjects business intelligence vulnerability
Published Dec 17, 2014
·Updated
SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SIPLATFORMSEARCHSERVERLOGONTOKEN token and gain privileges via a crafted CORBA call, aka SAP Note 2039905.
Affected Software
1 affected component
SAP BusinessObjects=4.1
Event History
Dec 17, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9387?
CVE-2014-9387 is classified as a medium severity vulnerability that allows privilege escalation.
2
How do I fix CVE-2014-9387?
To resolve CVE-2014-9387, you should apply the latest security patches provided by SAP for BusinessObjects Edge 4.1.
3
What types of attacks can exploit CVE-2014-9387?
CVE-2014-9387 can be exploited by remote attackers using crafted CORBA calls to gain unauthorized privileges.
4
Which software versions are affected by CVE-2014-9387?
CVE-2014-9387 specifically affects SAP BusinessObjects version 4.1.
5
What is the impact of CVE-2014-9387 on systems?
The impact of CVE-2014-9387 includes the potential for attackers to gain elevated privileges and unauthorized access to system resources.