vendor:
SAP GUI for Windows
by:
Digital Security Research Group [DSecRG]
8.8
CVSS
HIGH
File Overwriting
264
CWE
Product Name: SAP GUI for Windows
Affected Version From: 7100.2.7.1038 PL 7
Affected Version To: 7100.2.7.1038 PL 7
Patch Exists: YES
Related CWE: N/A
CPE: a:sap:sap_gui_for_windows
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
Digital Security Research Group [DSecRG] Advisory #DSECRG-09-044
SAP GUI for Windows 7.1 and 6.4 contains ActiveX component EAI WebViewer3D ( file WebViewer3D.dll) Lib GUID: {AFBBE070-7340-11d2-AA6B-00E02924C34E} which is contains insecure method that can overwrite any file in system. Attacker can construct html page which call one of the wulnerable functions such as SaveToSessionFile or SaveViewToSessionFile from ActiveX component EAI WebViewer3D.
Mitigation:
Update to the latest version of SAP GUI for Windows 7.1 and 6.4.