Vulnerabilities > CVE-2011-5154 - Unspecified vulnerability in SAP Graphical User Interface 6.4/7.2
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN sap
nessus
Summary
Multiple untrusted search path vulnerabilities in (1) SAPGui.exe and (2) BExAnalyzer.exe in SAP GUI 6.4 through 7.2 allow local users to gain privileges via a Trojan horse MFC80LOC.DLL file in the current working directory, as demonstrated by a directory that contains a .sap file. NOTE: some of these details are obtained from third party information.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Nessus
NASL family | Windows |
NASL id | SAP_GUI_NOTE1511179.NASL |
description | The remote host is running a version of SAP GUI that reportedly insecurely looks in its current working directory when resolving DLLs such as |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 72211 |
published | 2014-01-30 |
reporter | This script is Copyright (C) 2014-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/72211 |
title | SAP GUI DLL Loading Arbitrary Code Execution (Note 1511179) |
code |
|
References
- http://dsecrg.com/pages/vul/show.php?id=314
- http://secunia.com/advisories/43707
- http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a
- https://service.sap.com/sap/support/notes/1511179
- http://dsecrg.com/pages/vul/show.php?id=314
- https://service.sap.com/sap/support/notes/1511179
- http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a
- http://secunia.com/advisories/43707