SAP security note 1662272, "Potential denial of service in BusinessObjects Enterprise", is a note released on May 8, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can remotely exploit SAP BusinessObjects Enterprise to terminate it manually.
The issue is caused by a memory corruption that leads to process termination. A malicious user can trigger a condition where the process attempts to read outside its memory space, causing a memory protection fault. Consequently, the system terminates the process, making the application unusable until it is manually restarted.
Solution
Customers should install patch 2.10 to address this issue.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:N/I:N/A:P
Full note on SAP: SAP Support Launchpad note 1662272
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
