Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
Производитель ПО
Наименование ПО
SAP Notes
(1519966-3)
Описание
A buffer overflow vulnerability exists in NWBC 3.0 SmartClient. This enables a malicious user to inject code into the working memory that is subsequently executed by the application. It can also be used to cause a general fault in the product, thereby producing a termination of the product.
User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Как исправить
The NetWeaver Business client must be updated to Patch Level 4.
This patch fixes the buffer overrun. The patch blocks the Browser to use the malicious functions at all. The patch activates buffer security checks in the affected module.
This patch fixes the buffer overrun. The patch blocks the Browser to use the malicious functions at all. The patch activates buffer security checks in the affected module.
Ссылки