First published: Wed Dec 17 2014(Updated: )
SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and gain privileges via a crafted CORBA call, aka SAP Note 2039905.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9387 is classified as a medium severity vulnerability that allows privilege escalation.
To resolve CVE-2014-9387, you should apply the latest security patches provided by SAP for BusinessObjects Edge 4.1.
CVE-2014-9387 can be exploited by remote attackers using crafted CORBA calls to gain unauthorized privileges.
CVE-2014-9387 specifically affects SAP BusinessObjects version 4.1.
The impact of CVE-2014-9387 includes the potential for attackers to gain elevated privileges and unauthorized access to system resources.