ID

VAR-201410-1205


CVE

CVE-2014-8315


TITLE

SAP BusinessObjects Explorer Information Disclosure Vulnerability

Trust: 1.1

sources: IVD: c68cc40a-1eb4-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-06709 // BID: 70382

DESCRIPTION

polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 replies with different timing depending on if a connection can be made, which allows remote attackers to conduct port scanning attacks via a host name and port in the cms parameter. Business Objects is the world's leading business intelligence (BI) software company. SAP BusinessObjects Explorer is a browser that it launched. An information disclosure vulnerability exists in SAP BusinessObjects Explorer. This vulnerability could be exploited by an attacker to obtain a group host and its open port information. BusinessObjects Explorer14.0.5 (build 882) is vulnerable;other versions may also be affected

Trust: 2.61

sources: NVD: CVE-2014-8315 // JVNDB: JVNDB-2014-004936 // CNVD: CNVD-2014-06709 // BID: 70382 // IVD: c68cc40a-1eb4-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: c68cc40a-1eb4-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-06709

AFFECTED PRODUCTS

vendor:sapmodel:businessobjects explorerscope:eqversion:14.0.5

Trust: 1.6

vendor:sapmodel:businessobjects explorer (buildscope:eqversion:14.0.5882)

Trust: 0.9

vendor:sapmodel:businessobjects explorerscope:eqversion:14.0.5 build 882

Trust: 0.8

vendor:businessobjects explorermodel: - scope:eqversion:14.0.5

Trust: 0.2

sources: IVD: c68cc40a-1eb4-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-06709 // BID: 70382 // JVNDB: JVNDB-2014-004936 // CNNVD: CNNVD-201410-584 // NVD: CVE-2014-8315

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-8315
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-8315
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2014-06709
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201410-584
value: MEDIUM

Trust: 0.6

IVD: c68cc40a-1eb4-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

nvd@nist.gov: CVE-2014-8315
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-06709
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: c68cc40a-1eb4-11e6-abef-000c29c66e3d
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: c68cc40a-1eb4-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-06709 // JVNDB: JVNDB-2014-004936 // CNNVD: CNNVD-201410-584 // NVD: CVE-2014-8315

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.8

sources: JVNDB: JVNDB-2014-004936 // NVD: CVE-2014-8315

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201410-584

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201410-584

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-004936

PATCH

title:SAP Security Note 1908562url:http://scn.sap.com/docs/DOC-55451

Trust: 0.8

title:SAP BusinessObjects Explorer Information Disclosure Vulnerability Patchurl:https://www.cnvd.org.cn/patchInfo/show/50822

Trust: 0.6

sources: CNVD: CNVD-2014-06709 // JVNDB: JVNDB-2014-004936

EXTERNAL IDS

db:NVDid:CVE-2014-8315

Trust: 2.9

db:BIDid:70382

Trust: 2.5

db:CNVDid:CNVD-2014-06709

Trust: 0.8

db:CNNVDid:CNNVD-201410-584

Trust: 0.8

db:JVNDBid:JVNDB-2014-004936

Trust: 0.8

db:CXSECURITYid:WLB-2014100071

Trust: 0.6

db:XFid:96935

Trust: 0.6

db:IVDid:C68CC40A-1EB4-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: c68cc40a-1eb4-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-06709 // BID: 70382 // JVNDB: JVNDB-2014-004936 // CNNVD: CNNVD-201410-584 // NVD: CVE-2014-8315

REFERENCES

url:http://www.csnc.ch/misc/files/advisories/csnc-2013-016_sap_businessobjects_explorer_port-scanning.txt

Trust: 2.7

url:http://seclists.org/fulldisclosure/2014/oct/48

Trust: 1.6

url:http://www.securityfocus.com/bid/70382

Trust: 1.6

url:https://service.sap.com/sap/support/notes/1908562

Trust: 1.6

url:http://www.securityfocus.com/archive/1/533672/100/0/threaded

Trust: 1.0

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/96935

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-8315

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-8315

Trust: 0.8

url:http://cxsecurity.com/issue/wlb-2014100071

Trust: 0.6

url:http://www.securityfocus.com/archive/1/archive/1/533672/100/0/threaded

Trust: 0.6

url:http://xforce.iss.net/xforce/xfdb/96935

Trust: 0.6

url:http://www.sap.com

Trust: 0.3

sources: CNVD: CNVD-2014-06709 // BID: 70382 // JVNDB: JVNDB-2014-004936 // CNNVD: CNNVD-201410-584 // NVD: CVE-2014-8315

CREDITS

Stefan Horlacher

Trust: 0.3

sources: BID: 70382

SOURCES

db:IVDid:c68cc40a-1eb4-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2014-06709
db:BIDid:70382
db:JVNDBid:JVNDB-2014-004936
db:CNNVDid:CNNVD-201410-584
db:NVDid:CVE-2014-8315

LAST UPDATE DATE

2025-04-13T23:36:30.615000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-06709date:2014-10-14T00:00:00
db:BIDid:70382date:2015-04-13T21:01:00
db:JVNDBid:JVNDB-2014-004936date:2014-10-23T00:00:00
db:CNNVDid:CNNVD-201410-584date:2014-10-22T00:00:00
db:NVDid:CVE-2014-8315date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:IVDid:c68cc40a-1eb4-11e6-abef-000c29c66e3ddate:2014-10-14T00:00:00
db:CNVDid:CNVD-2014-06709date:2014-10-14T00:00:00
db:BIDid:70382date:2014-10-10T00:00:00
db:JVNDBid:JVNDB-2014-004936date:2014-10-23T00:00:00
db:CNNVDid:CNNVD-201410-584date:2014-10-22T00:00:00
db:NVDid:CVE-2014-8315date:2014-10-16T19:55:20.177