CVE-2015-2278: Buffer Overflow
The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to look-ups of non-simple codes, aka SAP Security Note 2124806, 2121661, 2127995, and 2125316.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2278?
CVE-2015-2278 is considered a medium severity vulnerability due to its potential to allow denial of service attacks.
How do I fix CVE-2015-2278?
To fix CVE-2015-2278, update to the latest version of affected SAP products as recommended by the vendor.
Which SAP products are affected by CVE-2015-2278?
CVE-2015-2278 affects SAP MaxDB 7.5 and 7.6, SAP NetWeaver Application Server for ABAP and Java, and related SDKs.
Can CVE-2015-2278 lead to data exposure?
CVE-2015-2278 primarily allows denial of service, so it does not directly lead to data exposure.
Is there a workaround for CVE-2015-2278?
There are no specific workarounds for CVE-2015-2278; applying updates is the recommended approach.