AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2015-2278

MEDIUM · CVSS 5 EPSS 2.13% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-06-02 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2015-2278
Severity
MEDIUM
CVSS
5
EPSS
2.13%
Java

Original NVD Description

The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to look-ups of non-simple codes, aka SAP Security Note 2124806, 2121661, 2127995, and 2125316.