vendor:
SAP GUI VSFlexGrid.VSFlexGridL
by:
Elazar Broad
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: SAP GUI VSFlexGrid.VSFlexGridL
Affected Version From: SAP GUI VSFlexGrid Activex Control sp<=14
Affected Version To: SAP GUI VSFlexGrid Activex Control sp<=14
Patch Exists: YES
Related CWE: N/A
CPE: a:sap:sap_gui_vsflexgrid_activex_control
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: SAP Business One 2007 Client, SAP Business One 2005 Client, SAP GUI 7.10 (7100.2.7.1038)
2007
Buffer Overflow in SAP GUI VSFlexGrid.VSFlexGridL
Component VSFlexGrid vulnerable to Buffer Overflow which was published in 2007 and not patched in SAPGUI untill this moment. This component and included in default SAPGUI installation. Attacker can construct html page which call vulnerable function "Acrchive" from ActiveX Object VSFlex7L with long parameter "ArcFileName".
Mitigation:
Patch the vulnerable component VSFlexGrid