E07-6gb01
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
2
Year:
2007
Description
This strike exploits a vulnerability in the SAP GUI's ActiveX control EAI WebViewer3D. The vulnerable parameter is the filePath string. Because it is not properly validated, an overly long value supplied for the filePath string, will overflow a stack buffer of 0x108, overwriting critical memory.