vendor:
SapGUI BI
by:
Metasploit
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: SapGUI BI
Affected Version From: 7100.1.400.8
Affected Version To: 7100.1.400.8
Patch Exists: YES
Related CWE: CVE-2009-4010
CPE: a:sap:sapgui_bi
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
SapGUI BI Tags Property Buffer Overflow
A buffer overflow vulnerability exists in the Tags property of the SapGUI BI ActiveX control (wadmxhtml.dl) when processing a specially crafted HTML page. An attacker can exploit this vulnerability to execute arbitrary code in the context of the user running the affected application. This vulnerability affects SapGUI BI versions 7100.1.400.8 and prior.
Mitigation:
Upgrade to the latest version of SapGUI BI.