CVE-2008-4830
SAP GUI <7.10.5 - RCE
Title source: llmDescription
Insecure method vulnerability in the KWEdit ActiveX control in SAP GUI 6.40 Patch 29 (KWEDIT.DLL 6400.1.1.41) and 7.10 Patch 5 (KWEDIT.DLL 7100.1.1.43) allows remote attackers to (1) overwrite arbitrary files via the SaveDocumentAs method or (2) read or execute arbitrary files via the OpenDocument method.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16493
metasploit
WORKING POC
EXCELLENT
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/enjoysapgui_comp_download.rb
References (6)
Scores
EPSS
0.6247
EPSS Percentile
98.4%
Details
Status
published
Products (2)
sap/sap_gui
6.40
sap/sap_gui
7.10
Published
Apr 16, 2009
Tracked Since
Feb 18, 2026