SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-2282

Stack-based buffer overflow in the LZC decompression implementation (CsObjectInt::CsDecomprLZC function in vpa106cslzc.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK,…

HIGH 7.5EPSS 3.52%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Stack-based buffer overflow in the LZC decompression implementation (CsObjectInt::CsDecomprLZC function in vpa106cslzc.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, aka SAP Security Note 2124806, 2121661, 2127995, and 2125316.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
3.52% probability · 89th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
sap/gui · sap/maxdb · sap/netweaver abap application server · sap/netweaver java application server · sap/netweaver rfc sdk · sap/rfc library
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.