CVE-2011-5154

3 documents3 sources
Severity
6.9MEDIUM
EPSS
0.1%
top 83.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 6
Latest updateMay 13

Description

Multiple untrusted search path vulnerabilities in (1) SAPGui.exe and (2) BExAnalyzer.exe in SAP GUI 6.4 through 7.2 allow local users to gain privileges via a Trojan horse MFC80LOC.DLL file in the current working directory, as demonstrated by a directory that contains a .sap file. NOTE: some of these details are obtained from third party information.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-qmgx-2mrg-pg77: Multiple untrusted search path vulnerabilities in (1) SAPGui2022-05-13
CVEList
CVE-2011-5154: Multiple untrusted search path vulnerabilities in (1) SAPGui2012-09-06
CVE-2011-5154 (MEDIUM CVSS 6.9) | Multiple untrusted search path vuln | cvebase.io