Memory Management Flaw in SAP 3D Visual Enterprise Author
CVE-2022-41166

5.5MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
11 October 2022

Summary

A vulnerability exists in SAP 3D Visual Enterprise Author that arises from inadequate memory management. When a user opens a manipulated Wavefront Object (.obj) file via ObjTranslator.exe from untrusted sources, the application may crash unexpectedly, leading to temporary unavailability. The user must restart the application to regain functionality, which can disrupt workflow and productivity.

Affected Version(s)

SAP 3D Visual Enterprise Author 9

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.