Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Memory Corruption vulnerability in SAP BusinessObjects Business Intelligence platform, SAP security note 2614229

SAP Note 2614229

SAP security note 2614229, "Memory Corruption vulnerability in SAP BusinessObjects Business Intelligence platform". Below are the symptom and SAP recommended solution.

Description

Symptom

SAP BusinessObjects Business Intelligence platform allows an attacker to leverage logical errors in memory management to cause a memory corruption.

Some well-known impacts of the Memory Corruption vulnerability include:

  • System information disclosure or system crash in worst cases
  • Vulnerability might have a direct impact on the confidentiality, integrity, and availability of a system
  • Information gathered can be used to craft further attacks, possibly with more severe consequences

Solution

This issue has been mitigated by checking the size of messages exchanged between client and server products.

The issue is fixed in the patches listed in the "Support Packages & Patches" section below. For Business Intelligence Platform maintenance schedule and strategy, see the Knowledge Base Article 2144559.

Reason and prerequisites

This issue can be triggered by exploiting a vulnerability present in the third-party open source Google Protobuf: CVE-2015-5237.

Note: It cannot be exploited on 32-bit versions of our product.

CVSS

Score 7.5 Vector: AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

References

Full note on SAP: SAP Support Launchpad note 2614229

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More