Memory Management Flaw in SAP 3D Visual Enterprise Author
CVE-2022-41166
5.5MEDIUM
Summary
A vulnerability exists in SAP 3D Visual Enterprise Author that arises from inadequate memory management. When a user opens a manipulated Wavefront Object (.obj) file via ObjTranslator.exe from untrusted sources, the application may crash unexpectedly, leading to temporary unavailability. The user must restart the application to regain functionality, which can disrupt workflow and productivity.
Affected Version(s)
SAP 3D Visual Enterprise Author 9
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved