HTTP: SAPGui BusinessObjects BI Unsafe ActiveX Control Method

This signature detects attempts to use unsafe ActiveX controls in SAPGui BusinessObjects. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

SAPGui BusinessObjects BI is prone to a heap-based buffer-overflow vulnerability because the application fails to adequately check boundaries on user-supplied input. An attacker can exploit this issue to execute arbitrary code in the context of the application, typically Internet Explorer, using the ActiveX control. Failed attacks will likely cause denial-of-service conditions. SAPGui BusinessObjects BI 7100.1.400.8 is vulnerable; other versions may be affected.

Affected Products

Sap sapgui_businessobjects_bi

Short Name
HTTP:STC:ACTIVEX:SAPGUI-AX
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ActiveX BI BusinessObjects Control Method SAPGui Unsafe bid:41715
Release Date
08/09/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Sap

Found a potential security threat?