CVE-2015-2282: Buffer Overflow
Stack-based buffer overflow in the LZC decompression implementation (CsObjectInt::CsDecomprLZC function in vpa106cslzc.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, aka SAP Security Note 2124806, 2121661, 2127995, and 2125316.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2282?
CVE-2015-2282 has been classified with a medium severity due to the potential for a stack-based buffer overflow.
How do I fix CVE-2015-2282?
To fix CVE-2015-2282, update to the latest versions of SAP MaxDB, Netweaver Application Servers, and related products that address this vulnerability.
What products are affected by CVE-2015-2282?
CVE-2015-2282 affects SAP MaxDB versions 7.5 and 7.6, as well as various SAP NetWeaver applications and SDKs.
What are the consequences of exploiting CVE-2015-2282?
Exploitation of CVE-2015-2282 can lead to denial of service or remote code execution depending on the system configuration.
When was CVE-2015-2282 disclosed?
CVE-2015-2282 was disclosed in May 2015.