vendor:
Hyperion Smart View for Office
by:
sajith
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Hyperion Smart View for Office
Affected Version From: 11.1.2.3.000
Affected Version To: 11.1.2.3.000
Patch Exists: YES
Related CWE: CVE-2015-2572
CPE: a:oracle:hyperion_smart_view_for_office
Metasploit:
N/A
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=83033, https://www.infosecmatter.com/nessus-plugin-library/?id=82025, https://www.infosecmatter.com/nessus-plugin-library/?id=82835, https://www.infosecmatter.com/nessus-plugin-library/?id=82834, https://www.infosecmatter.com/nessus-plugin-library/?id=92994, https://www.infosecmatter.com/nessus-plugin-library/?id=82923, https://www.infosecmatter.com/nessus-plugin-library/?id=82836, https://www.infosecmatter.com/nessus-plugin-library/?id=83558, https://www.infosecmatter.com/nessus-plugin-library/?id=82514, https://www.infosecmatter.com/nessus-plugin-library/?id=93294
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows 7 Enterprise 6.1.7601 Service Pack 1 [x64],en-us
2014
Buffer Overflow in Oracle? Hyperion Smart View for Office [DOS]
A buffer overflow vulnerability exists in Oracle? Hyperion Smart View for Office Fusion Edition 11.1.2.3.000 Build 157 when a large value is entered into the 'Shared Connections URL' field in the 'Options' menu. This can be exploited by any Microsoft Office product such as Excel, Word, or PowerPoint. The output of the crash analyzed in the debugger is shown in the text.
Mitigation:
Oracle released a patch on April 14, 2015 to address this vulnerability.