Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 does not limit the number of CUIDs that may be requested, which allows remote authenticated users to cause a denial of service via a large numCuids value in a GenerateCuids SOAPAction to the dswsbobje/services/biplatform URI.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Businessobjects | Sap | 3.2 (including) | 3.2 (including) |