• Все разделы
  • Статьи
  • Медиа
  • Новости
  • Нормативные материалы
  • Конференции
  • Глоссарий

Не установлено обновление Note 1432880

Главная Специалистам База уязвимостей Не установлено обновление Note 1432880

Карточка уязвимости

Характеристики уязвимости

Уровень опасности
Оценка CVSS
Производитель ПО
SAP
Наименование ПО
SAP Notes (1432880-3)
Описание
A buffer overflow vulnerability exists in Crystal Reports Servers. This  enables a malicious user to inject code into the working memory that is  subsequently executed by the application. It can also be used to cause a  general fault in the product, thereby producing a termination of the product.
Как исправить
XIr3 customers should install FP2.6
BOE Edge customers should install FP2.1
XIR2 customers should install FP6.2

Temporary Workaround:
Customers are recommended to refer to the administration guide, chapter 5 - working with firewalls, to implement firewall protection as a workaround. Customers can also temporarily delete crheapalloc.dll from the system until the patch is installed, however this can cause some performance degradation for Crystal Reports workflows. The crheapalloc.dll file MUST be put back on the system if it has been deleted for the workaround before installing the patch containing the fix.
Ссылки