First published: Wed Apr 01 2009(Updated: )
Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Level 9 allows remote attackers to execute arbitrary code via a long argument to the SaveViewToSessionFile method.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP User Interface (UI) | ||
SAP User Interface (UI) | <=7.10 | |
SAP User Interface (UI) | =4.6 | |
SAP User Interface (UI) | =4.6 | |
SAP User Interface (UI) | =4.6a | |
SAP User Interface (UI) | =4.6a | |
SAP User Interface (UI) | =4.6b | |
SAP User Interface (UI) | =4.6b | |
SAP User Interface (UI) | =4.6c | |
SAP User Interface (UI) | =4.6c | |
SAP User Interface (UI) | =4.6d | |
SAP User Interface (UI) | =4.6d | |
SAP User Interface (UI) | =6.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4475 is considered a critical vulnerability due to its potential for remote code execution.
To fix CVE-2007-4475, upgrade SAPgui to version 7.10 Patch Level 9 or later.
CVE-2007-4475 affects all versions of SAPgui prior to 7.10 Patch Level 9 and specific earlier versions like 4.6 and 6.40.
The attack vector for CVE-2007-4475 is remote, as it can be exploited via a crafted argument sent to the SaveViewToSessionFile method.
Yes, due to the nature of the vulnerability, exploitation of CVE-2007-4475 could potentially lead to data loss or corruption.