vendor:
Oracle Hyperion Suite
by:
rgod
7.5
CVSS
HIGH
Stack Based Buffer Overflow
CWE
Product Name: Oracle Hyperion Suite
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Oracle DataDirect ODBC Drivers HOST Attribute arsqls24.dll Stack Based Buffer Overflow PoC
This proof-of-concept (PoC) creates a .oce file that can be used to exploit a stack-based buffer overflow vulnerability in Hyperion Interactive Reporting Studio, which is part of the Oracle Hyperion Suite. When the file is clicked, a login box appears followed by an error message, leading to a crash.
Mitigation:
Apply the latest patch provided by Oracle.