VulnerabilityModified
CVE-2010-4556
Stack-based buffer overflow in the SapThemeRepository ActiveX control (sapwdpcd.dll) in SAP NetWeaver Business Client allows remote attackers to execute arbitrary code via the (1) Load and (2) LoadTheme methods.
HIGH 9.3EPSS 6.15%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.15%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Stack-based buffer overflow in the SapThemeRepository ActiveX control (sapwdpcd.dll) in SAP NetWeaver Business Client allows remote attackers to execute arbitrary code via the (1) Load and (2) LoadTheme methods.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 6.15% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- sap/netweaver business client
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/35796Vendor Advisory
- http://www.securityfocus.com/bid/45396
- http://www.securitytracker.com/id?1024890
- http://www.vupen.com/english/advisories/2010/3239Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-10-290/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64061
- https://service.sap.com/sap/support/notes/1519966
- http://secunia.com/advisories/35796Vendor Advisory
- http://www.securityfocus.com/bid/45396
- http://www.securitytracker.com/id?1024890
- http://www.vupen.com/english/advisories/2010/3239Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-10-290/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64061
- https://service.sap.com/sap/support/notes/1519966
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.