CVE-2015-2278
Estado: ModificadaMedia (5)—
The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to look-ups of non-simple codes, aka SAP Security Note 2124806, 2121661, 2127995, and 2125316.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.13%
- Percentil entre todas las CVEs puntuadas: 81
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (6)
CWE
- CWE-119
Referencias
- http://packetstormsecurity.com/files/131883/SAP-LZC-LZH-Compression-Denial-Of-Service.html
- http://seclists.org/fulldisclosure/2015/May/50
- http://seclists.org/fulldisclosure/2015/May/96
- http://www.coresecurity.com/advisories/sap-lzc-lzh-compression-multiple-vulnerabilities
- http://www.securityfocus.com/archive/1/535535/100/0/threaded
- http://www.securityfocus.com/bid/74643
- http://packetstormsecurity.com/files/131883/SAP-LZC-LZH-Compression-Denial-Of-Service.html
- http://seclists.org/fulldisclosure/2015/May/50
- http://seclists.org/fulldisclosure/2015/May/96
- http://www.coresecurity.com/advisories/sap-lzc-lzh-compression-multiple-vulnerabilities
- http://www.securityfocus.com/archive/1/535535/100/0/threaded
- http://www.securityfocus.com/bid/74643
JSON original (NVD)
Mostrar
{
"id": "CVE-2015-2278",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2015-06-02T14:59:07.537",
"references": [
{
"url": "http://packetstormsecurity.com/files/131883/SAP-LZC-LZH-Compression-Denial-Of-Service.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2015/May/50",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2015/May/96",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.coresecurity.com/advisories/sap-lzc-lzh-compression-multiple-vulnerabilities",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/535535/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/74643",
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.com/files/131883/SAP-LZC-LZH-Compression-Denial-Of-Service.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2015/May/50",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2015/May/96",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.coresecurity.com/advisories/sap-lzc-lzh-compression-multiple-vulnerabilities",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/535535/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/74643",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to look-ups of non-simple codes, aka SAP Security Note 2124806, 2121661, 2127995, and 2125316."
},
{
"lang": "es",
"value": "La implementación LZH decompression (la función CsObjectInt::BuildHufTree en vpa108csulzh.cpp) en SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, la herramienta de archivos SAPCAR, y otros productos permite a atacantes dependientes de contexto causar una denegación de servicio (lectura fuera de rango) a través de vectores no especificados, relacionado con búsquedas de códigos no simples, también conocido como las notas de seguridad de SAP 2124806, 2121661, 2127995, y 2125316."
}
],
"lastModified": "2026-06-17T00:23:51.200",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:gui:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "399383D3-01CC-48FF-943F-F7F0EF54ECFC"
},
{
"criteria": "cpe:2.3:a:sap:maxdb:7.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BAA8EB08-6866-4FDF-A552-C290A54E9B08"
},
{
"criteria": "cpe:2.3:a:sap:maxdb:7.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3BF72173-A7B4-44DD-A842-BA29D6AF6E08"
},
{
"criteria": "cpe:2.3:a:sap:netweaver_abap_application_server:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9A55F8F2-A31D-4C57-A664-0B1DBD1F17A9"
},
{
"criteria": "cpe:2.3:a:sap:netweaver_java_application_server:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4BC67018-106D-4103-83FB-FEC80496F14D"
},
{
"criteria": "cpe:2.3:a:sap:netweaver_rfc_sdk:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1A37353F-8BC1-4B72-B452-E19308C9740B"
},
{
"criteria": "cpe:2.3:a:sap:rfc_library:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F0FE182C-229B-461B-8139-D39E005034A3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}