|
SAP BusinessObjects contains a flaw that may allow a remote denial of service. The program fails to limit how many CUIDs may be requested. This will allow a remote authenticated attacker to specify a large numCuids value in a GenerateCuids SOAPAction to the 'dswsbobje/services/biplatform' URI, which will exhaust the available resources and result in a loss of availability.
|