CVE-2008-4830
EnjoySAP SAP GUI - ActiveX Control Arbitrary File Download
Severity Score
9.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Insecure method vulnerability in the KWEdit ActiveX control in SAP GUI 6.40 Patch 29 (KWEDIT.DLL 6400.1.1.41) and 7.10 Patch 5 (KWEDIT.DLL 7100.1.1.43) allows remote attackers to (1) overwrite arbitrary files via the SaveDocumentAs method or (2) read or execute arbitrary files via the OpenDocument method.
Vulnerabilidad de método inseguro en el control ActiveX KWEdit en SAP GUI v6.40 Patch 29 (KWEDIT.DLL v6400.1.1.41) y v7.10 Patch 5 (KWEDIT.DLL v7100.1.1.43) permite a atacantes remotos (1) sobreescribir ficheros de su elección mediante el método SaveDocumentAs o (2) leer y ejecutar ficheros de su elección mediante el método OpenDocument.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2008-10-31 CVE Reserved
- 2009-04-15 CVE Published
- 2010-12-01 First Exploit
- 2024-08-07 CVE Updated
- 2024-10-25 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/archive/1/502698/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/34524 | Vdb Entry | |
http://www.securitytracker.com/id?1022062 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/16493 | 2010-12-01 |
URL | Date | SRC |
---|---|---|
http://www.vupen.com/english/advisories/2009/1043 | 2018-10-11 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/32869 | 2018-10-11 | |
http://secunia.com/secunia_research/2008-56 | 2018-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Sap Gui Search vendor "Sap" for product "Sap Gui" | 6.40 Search vendor "Sap" for product "Sap Gui" and version "6.40" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Sap Gui Search vendor "Sap" for product "Sap Gui" | 7.10 Search vendor "Sap" for product "Sap Gui" and version "7.10" | - |
Affected
|