The InformationWeek -- Blogs

Security

Topics:   Security

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Serious Flaw Leaves SAP Users Vulnerable


Posted by George Hulme, Nov 11, 2008 09:06 PM

The US-CERT is warning SAP users of a flaw that could make it possible for systems to succumb to remote, unauthenticated attacks.


According to US-CERT, the flaw resides within the SAPgui, SAP's software graphic user interface. More specifically, within an ActiveX control, MDrmSap within the mdrmsap.dll file. US-CERT says the MDrmSap ActiveX control contains an "unspecified" flaw that causes Internet Explorer to crash in a way that is exploitable when it tries to launch the library.

Here's the impact, from a recently published vulnerability note:

By convincing a user to view a specially crafted HTML document (e.g., a Web page or an HTML e-mail message or attachment), an attacker may be able to execute arbitrary code with the privileges of the user. The attacker could also cause Internet Explorer (or the program using the WebBrowser control) to crash.

Fortunately, there's a patch, which is available from SAP (authentication required.)

Users unable to apply the patch, for whatever reason, also can disable the MDrmSap ActiveX control in Internet Explorer, or disable ActiveX altogether.

« Google Flu Trends | Main | Over $9K In Prizes Up For Grabs At Mashup Camp This Monday »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. HPC Joins the Dummy Revolution?
  2. Detecting Scalability Problems With Intel Parallel Universe Portal
  3. Just Say No To SFAQL Parallelism


Join The InformationWeek Group On LinkedIn


                           


  1. Top Resources To Save Big On Cyber Monday
  2. AT&T, T-Mobile, Verizon All Offering Black Friday Sales
  3. Verizon Snags Samsung's Omnia II With WinMo 6.5
  4. Murdoch And Microsoft Redefine Search
  5. Thoughts On The Motorola Droid


  1. IBM Buys Database Security Company
  2. Online Shopping Gains Following Black Friday
  3. Survey: Android Developers Unhappy
  4. Large Hadron Collider Breaks Energy Record
  5. AT&T, LG Intro 1 GHz Smartphone
  6. Dell Dabbles With Chrome OS

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007