|
|||
Rule General Information |
---|
Release Date: | 2019-07-05 | |
Rule Name: | EnjoySAP GUI ActiveX control File Download Vulnerability (CVE-2008-4830) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Insecure method vulnerability in the KWEdit ActiveX control in SAP GUI 6.40 Patch 29 (KWEDIT.DLL 6400.1.1.41) and 7.10 Patch 5 (KWEDIT.DLL 7100.1.1.43) allows remote attackers to (1) overwrite arbitrary files via the SaveDocumentAs method or (2) read or execute arbitrary files via the OpenDocument method. | |
Impact: | An attacker could exploit this vulnerability to have unspecified effect. | |
Affected OS: | Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others | |
Reference: | SecurityFocusBID:34524 http://www.securityfocus.com/archive/1/502698/100/0/threaded SecurityTrackerID:1022062 http://www.vupen.com/english/advisories/2009/1043 |
|
Solutions |
---|
The vendors have released upgrade patches to fix vulnerabilities, please visit: https://service.sap.com/sap/support/notes/1294913 |