← Back

CVE-2011-5154

nvd nist
Published: Sep 6, 2012Modified: Apr 29, 2026

JSON object

Loading...
6.9
Vector
AV:L/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 3.4 / Impact: 10.0
Source: NVD

Description

Multiple untrusted search path vulnerabilities in (1) SAPGui.exe and (2) BExAnalyzer.exe in SAP GUI 6.4 through 7.2 allow local users to gain privileges via a Trojan horse MFC80LOC.DLL file in the current working directory, as demonstrated by a directory that contains a .sap file. NOTE: some of these details are obtained from third party information.

Affected (2)

1 product
Graphical User Interface
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 6.4
Version 7.2

References (8)

Timeline

No history available yet.