PT-2009-1253 · Sap · Sap Gui

Publicado

2009-04-16

·

Atualizado

2018-10-11

·

CVE-2008-4830

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SAP GUI versions 6.40 Patch 29 and 7.10 Patch 5
Description The issue allows remote attackers to overwrite arbitrary files via the SaveDocumentAs method or read and execute arbitrary files via the OpenDocument method in the KWEdit ActiveX control.
Recommendations For SAP GUI version 6.40 Patch 29, consider disabling the SaveDocumentAs and OpenDocument methods in the KWEdit ActiveX control until a patch is available. For SAP GUI version 7.10 Patch 5, consider disabling the SaveDocumentAs and OpenDocument methods in the KWEdit ActiveX control until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2008-4830

Produtos afetados

Sap Gui