First published: Thu Apr 16 2009(Updated: )
Insecure method vulnerability in the KWEdit ActiveX control in SAP GUI 6.40 Patch 29 (KWEDIT.DLL 6400.1.1.41) and 7.10 Patch 5 (KWEDIT.DLL 7100.1.1.43) allows remote attackers to (1) overwrite arbitrary files via the SaveDocumentAs method or (2) read or execute arbitrary files via the OpenDocument method.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Sap Gui | =7.10 | |
Sap Sap Gui | =6.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4830 is classified as a critical vulnerability due to its ability to allow remote attackers to overwrite arbitrary files.
To mitigate CVE-2008-4830, users should upgrade to the latest patches provided by SAP for both versions of SAP GUI.
CVE-2008-4830 affects SAP GUI versions 6.40 and 7.10.
The potential impacts of CVE-2008-4830 include unauthorized file access, file overwriting, and potential system compromise.
CVE-2008-4830 is a remote vulnerability, allowing attackers to exploit it over a network.