vendor:
SAP GUI for Windows
by:
Mark Litchfield
7.5
CVSS
HIGH
Heap Overflow
CWE
Product Name: SAP GUI for Windows
Affected Version From:
Affected Version To:
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: Windows
2007
EnjoySAP, SAP GUI for Windows – Heap Overflow
When installing EnjoySAP, in appreciation of its vast size for being a client (around 500MB), there are an astounding 1102 ActiveX controls installed. A relatively brief examination of these controls found a large number of instances that would terminate EnjoySAP process, there were a number that could create files on the file system (there unfortunately exists no ability to inject content into these created files) and a number of buffer overruns.