CVE-2011-5154: SAP Graphical User Interface
Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.
Multiple untrusted search path vulnerabilities in (1) SAPGui.exe and (2) BExAnalyzer.exe in SAP GUI 6.4 through 7.2 allow local users to gain privileges via a Trojan horse MFC80LOC.DLL file in the current working directory, as demonstrated by a directory that contains a .sap file. NOTE: some of these details are obtained from third party information.
Affected products
- SAP Graphical User Interface: version 6.4 only; version 7.2 only
Published 2012-09-06. Last modified 2026-06-16.