Serious Flaw Leaves SAP Users VulnerableSerious Flaw Leaves SAP Users Vulnerable
The US-CERT is warning SAP users of a flaw that could make it possible for systems to succumb to remote, unauthenticated attacks.
November 11, 2008

The US-CERT is warning SAP users of a flaw that could make it possible for systems to succumb to remote, unauthenticated attacks.According to US-CERT, the flaw resides within the SAPgui, SAP's software graphic user interface. More specifically, within an ActiveX control, MDrmSap within the mdrmsap.dll file. US-CERT says the MDrmSap ActiveX control contains an "unspecified" flaw that causes Internet Explorer to crash in a way that is exploitable when it tries to launch the library.
Here's the impact, from a recently published vulnerability note:
"By convincing a user to view a specially crafted HTML document (e.g., a Web page or an HTML e-mail message or attachment), an attacker may be able to execute arbitrary code with the privileges of the user. The attacker could also cause Internet Explorer (or the program using the WebBrowser control) to crash."
Fortunately, there's a patch, which is available from SAP (authentication required.)
Users unable to apply the patch, for whatever reason, also can disable the MDrmSap ActiveX control in Internet Explorer, or disable ActiveX altogether.
About the Author(s)
You May Also Like
Hacking Your Digital Identity: How Cybercriminals Can and Will Get Around Your Authentication Methods
Oct 26, 2023Modern Supply Chain Security: Integrated, Interconnected, and Context-Driven
Nov 06, 2023How to Combat the Latest Cloud Security Threats
Nov 06, 2023Reducing Cyber Risk in Enterprise Email Systems: It's Not Just Spam and Phishing
Nov 01, 2023SecOps & DevSecOps in the Cloud
Nov 06, 2023