SAP security note 2614229, "Memory Corruption vulnerability in SAP BusinessObjects Business Intelligence platform". Below are the symptom and SAP recommended solution.
Description
Symptom
SAP BusinessObjects Business Intelligence platform allows an attacker to leverage logical errors in memory management to cause a memory corruption.
Some well-known impacts of the Memory Corruption vulnerability include:
- System information disclosure or system crash in worst cases
- Vulnerability might have a direct impact on the confidentiality, integrity, and availability of a system
- Information gathered can be used to craft further attacks, possibly with more severe consequences
Solution
This issue has been mitigated by checking the size of messages exchanged between client and server products.
The issue is fixed in the patches listed in the "Support Packages & Patches" section below. For Business Intelligence Platform maintenance schedule and strategy, see the Knowledge Base Article 2144559.
Reason and prerequisites
This issue can be triggered by exploiting a vulnerability present in the third-party open source Google Protobuf: CVE-2015-5237.
Note: It cannot be exploited on 32-bit versions of our product.
CVSS
Score 7.5 Vector: AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
References
Full note on SAP: SAP Support Launchpad note 2614229
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




