Security Advisory

CVE-2011-5154

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2012-09-06 10:00:00
Last updated 2024-09-16 19:37:08
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Multiple untrusted search path vulnerabilities in (1) SAPGui.exe and (2) BExAnalyzer.exe in SAP GUI 6.4 through 7.2 allow local users to gain privileges via a Trojan horse MFC80LOC.DLL file in the current working directory, as demonstrated by a directory that contains a .sap file. NOTE: some of these details are obtained from third party information.