PT-2009-1253 · Sap · Sap Gui

Published

2009-04-16

·

Updated

2018-10-11

·

CVE-2008-4830

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SAP GUI versions 6.40 Patch 29 and 7.10 Patch 5
Description The issue allows remote attackers to overwrite arbitrary files via the SaveDocumentAs method or read and execute arbitrary files via the OpenDocument method in the KWEdit ActiveX control.
Recommendations For SAP GUI version 6.40 Patch 29, consider disabling the SaveDocumentAs and OpenDocument methods in the KWEdit ActiveX control until a patch is available. For SAP GUI version 7.10 Patch 5, consider disabling the SaveDocumentAs and OpenDocument methods in the KWEdit ActiveX control until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2008-4830

Affected Products

Sap Gui