CVE-2009-4988

SAP Business One 2005-a - Memory Corruption

Title source: rule

Description

Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote attackers to execute arbitrary code via a long GIOP request to TCP port 30000.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16423
exploitdb WORKING POC VERIFIED
by Bruk0ut · pythonremotewindows
https://www.exploit-db.com/exploits/9319
metasploit WORKING POC GREAT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/sap_2005_license.rb

Scores

EPSS 0.7968
EPSS Percentile 99.1%

Details

CWE
CWE-119
Status published
Products (2)
sap/business_one_2005-a 6.80.123
sap/business_one_2005-a 6.80.320
Published Aug 25, 2010
Tracked Since Feb 18, 2026