SAP security note 2265964, “Deserialization of untrusted data in BI Platform”. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP BusinessObjects BI Platform uses an Open Source component apache commons-collection 3.x which deserializes untrusted data without sufficiently verifying that resulting data will be valid.
This weakness may lead to remote command execution or denial of service vulnerability.
Solution
This issue is fixed in the patches listed in the “Support Packages & Patches” section below. The “Support Packages & Patches” section will be populated with the relevant patch levels once they are released. For Business Intelligence Platform maintenance schedule and strategy see the Knowledge Base Article 2144559 in the References section.
CVSS
Score 7.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
References
Full note on SAP: SAP Support Launchpad note 2265964
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




