An insecure method was found in SAPBExCommonResources (class BExGlobal) shipped with the ActiveX control component that is part of SAP's GUI. One of the methods (Execute) can be used to execute files on the system.
Patch Availability:
All patches are available since December via note 1407285.
Disclosure Timeline:
Reported: 16.10.2009
Vendor response: 27.10.2009
Date of Public Advisory: 23.03.2010