US-CERT warns of SAP vulnerability

By Tom Espiner, ZDNet UK
Wednesday, November 12, 2008 07:52 AM

The U.S. Computer Emergency Readiness Team has warned of a vulnerability in SAP GUI, the graphical user interface client in SAP's enterprise resource planning software.

The unspecified flaw can cause Internet Explorer (IE) to crash in an exploitable manner. The flaw lies in an ActiveX control called MDrmSap, a component of SAP GUI.

The U.S. Computer Emergency Readiness Team (U.S.-CERT) warned in an SAP Note 1142431. Login is required to access the patch.

Workarounds include disabling the MDrmSap ActiveX control in IE by setting the IE killbit for CLSID {B01952B0-AF66-11D1-B10D-0060086F6D97}, or IT professionals could disable IE ActiveX controls completely.

Security company Secunia warned in an advisory that the flaw was "highly critical". Versions of SAP GUI affected are 6.x and 7.x, according to Secunia.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Employ smoke tests at the start of your testing process

Web Development

The most basic tests any software developer must run are smoke tests, which are a set of written, non-exhaustive tests that only deal with the most functional aspects of a software application or process.


Read more »



What will social analytics say about your company?

Blog thumbnail

I was finally able to set aside some time the other night to reassess my privacy settings in Facebook, following changes made to the social network's privacy policy in December...... by Eileen Yu

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. google inc.
  7. internet
  8. malware
  9. microsoft corp.
  10. microsoft windows
  11. network
  12. network security
  13. pc security
  14. researcher
  15. security
  16. security management
  17. software
  18. spam and phishing
  19. viruses and worms
  20. web