Sap Gui
Vendor:
First CVE: Apr 15, 2004 · Active for 22 years
8
Total CVEs
More Total CVEs than 49% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 85% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Sap Gui over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 15, 2004
22 years ago
Most Recent CVE
Apr 16, 2009
6,308 days ago
CVE Severity & Scoring
Sap Gui8 CVEs
13%
88%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown8 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown8 (100.0%)
User Interaction
None0 (0.0%)
Unknown8 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (100.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0621HIGH Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to execute arbitrary code via long arguments to the (1) 0x01, | Feb 6, 2008 | 7.5 | 78 | NO | YES |
CVE-2007-4475HIGH Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Level 9 allows remote attackers to execute arbitrary code via a | Apr 1, 2009 | 9.3 | 64 | NO | YES |
CVE-2008-4830HIGH Insecure method vulnerability in the KWEdit ActiveX control in SAP GUI 6.40 Patch 29 (KWEDIT.DLL 6400.1.1.41) and 7.10 Patch 5 (KWEDIT.DLL 7100.1.1.43) allows remote attackers to ( | Apr 16, 2009 | 9.3 | 56 | NO | YES |
CVE-2008-4387HIGH Unspecified vulnerability in the Simba MDrmSap ActiveX control in mdrmsap.dll in SAP SAPgui allows remote attackers to execute arbitrary code via unknown vectors involving instanti | Nov 10, 2008 | 9.3 | 29 | NO | NO |
CVE-2008-0620HIGH SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to cause a denial of service (crash) via a 0x53 LPD command, which causes the ser | Feb 6, 2008 | 10.0 | 27 | NO | NO |
CVE-2008-4827HIGH Multiple heap-based buffer overflows in the AddTab method in the (1) Tab and (2) CTab ActiveX controls in c1sizer.ocx and the (3) TabOne ActiveX control in sizerone.ocx in Componen | Jan 8, 2009 | 9.3 | 25 | NO | NO |
CVE-2003-1035HIGH The default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a brute force password guessing at | Apr 15, 2004 | 7.5 | 19 | NO | NO |
CVE-2002-1579MEDIUM SAP GUI (Sapgui) 4.6D allows remote attackers to cause a denial of service (crash) via a connection to a high-numbered port, which generates an "unknown connection data" error. | Apr 15, 2004 | 5.0 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
37.5% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
37.5% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.10 | 4 | 9.0 | 27.8% | 0 | 2 |
| 6.40 | 3 | 9.3 | 24.9% | 0 | 2 |
| 4.6d | 3 | 7.8 | 20.9% | 0 | 1 |
| 4.6c | 3 | 7.8 | 20.9% | 0 | 1 |
| 4.6b | 2 | 7.9 | 27.4% | 0 | 1 |
| 4.6a | 2 | 7.9 | 27.4% | 0 | 1 |
| 4.6 | 2 | 7.9 | 27.4% | 0 | 1 |