CVE-2015-7730
https://notcve.org/view.php?id=CVE-2015-7730
SAP BusinessObjects BI Platform 4.1, BusinessObjects Edge 4.0, and BusinessObjects XI (BOXI) 3.1 R3 allow remote attackers to cause a denial of service (out-of-bounds read and listener crash) via a crafted GIOP packet, aka SAP Security Note 2001108. SAP BusinessObjects BI Platform 4.1, BusinessObjects Edge 4.0 y BusinessObjects XI (BOXI) 3.1 R3 permite a atacantes remotos causar una denegación de servicio (lectura fuera de limite y caída del receptor) a través de un paquete GIOP manipulado, también conocido como SAP Security Note 2001108. • http://seclists.org/fulldisclosure/2015/Sep/81 http://www.securitytracker.com/id/1033637 https://www.onapsis.com/blog/analyzing-sap-security-notes-may-2015-edition https://www.onapsis.com/research/security-advisories/SAP-Business-Objects-Memory-Corruption • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2014-8309
https://notcve.org/view.php?id=CVE-2014-8309
SAP BusinessObjects 4.0 and BusinessObjects XI (BOXI) R2 and 3.1 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to enumerate valid usernames via SecEnterprise authentication requests to the Session web service. SAP BusinessObjects 4.0 y BusinessObjects XI (BOXI) R2 y 3.1 generan mensajes de error tras un intento de inicio de sesión fallido con diferente tiempo de retraso dependiendo de si la cuenta de usuario existe o no, lo que permite a atacantes remotos enumerar nombres de usuario válidos a través de peticiones de autenticación SecEnterprise al servicio web Session. • http://scn.sap.com/docs/DOC-8218 http://seclists.org/fulldisclosure/2014/Oct/42 http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-029 http://www.securityfocus.com/archive/1/533647/100/0/threaded http://www.securityfocus.com/bid/70304 https://exchange.xforce.ibmcloud.com/vulnerabilities/96874 https://service.sap.com/sap/support/notes/2001109 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •