vendor:
SAP GUI for Windows
by:
Alexander Polyakov
7.5
CVSS
HIGH
Buffer Overflow
119 (Buffer Overflow)
CWE
Product Name: SAP GUI for Windows
Affected Version From: 6.4
Affected Version To: 6.4
Patch Exists: NO
Related CWE:
CPE: sap:gui_for_windows
Platforms Tested: Windows
2009
SAP GUI for Windows Buffer Overflow Vulnerability
SAP GUI for Windows version 6.4 contains an ActiveX component called SAPIrRfc which is vulnerable to a buffer overflow attack. An attacker can construct an HTML page that calls the vulnerable function 'Accept' from the ActiveX Object SAPIrRfc with a long parameter. When a user opens this page, it can lead to a denial of service (DoS) or full remote control of the target system. An example of a DoS attack is provided in the advisory.
Mitigation:
Update SAP GUI for Windows to a version that is not affected by this vulnerability. Apply necessary security patches as advised by the vendor.