EnjoySAP Multiple ActiveX Controls Multiple Unspecified Vulnerabilities
BID:24776
Info
EnjoySAP Multiple ActiveX Controls Multiple Unspecified Vulnerabilities
| Bugtraq ID: | 24776 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3607 CVE-2007-3608 CVE-2007-3605 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2007 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | Mark Litchfield reported these issues. |
| Vulnerable: |
SAP EnjoySAP 0 |
| Not Vulnerable: | |
Discussion
EnjoySAP Multiple ActiveX Controls Multiple Unspecified Vulnerabilities
EnjoySAP is prone to multiple unspecified vulnerabilities affecting multiple ActiveX controls. These vulnerabilities include multiple denial-of-service issues, buffer-overflow issues, and other issues that can allow attackers to create arbitrary files on an affected computer.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of an application using the ActiveX control, to create arbitrary files, or to trigger denial-of-service conditions.
NOTE: Currently, very few details are available regarding these issues. We will update this BID as more information emerges. Individual issues may be split into separate BIDs.
EnjoySAP is prone to multiple unspecified vulnerabilities affecting multiple ActiveX controls. These vulnerabilities include multiple denial-of-service issues, buffer-overflow issues, and other issues that can allow attackers to create arbitrary files on an affected computer.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of an application using the ActiveX control, to create arbitrary files, or to trigger denial-of-service conditions.
NOTE: Currently, very few details are available regarding these issues. We will update this BID as more information emerges. Individual issues may be split into separate BIDs.
Exploit / POC
EnjoySAP Multiple ActiveX Controls Multiple Unspecified Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting user to access a malicious webpage.
To exploit these issues, an attacker must entice an unsuspecting user to access a malicious webpage.
Solution / Fix
EnjoySAP Multiple ActiveX Controls Multiple Unspecified Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
EnjoySAP Multiple ActiveX Controls Multiple Unspecified Vulnerabilities
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- SAP Homepage (SAP)
- EnjoySAP, SAP GUI for Windows - Stack Overflow (NGS Software Insight Security Research)