Memory Management Flaw in SAP 3D Visual Enterprise Author
CVE-2022-41178

5.5MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
11 October 2022

Summary

A vulnerability has been identified in SAP 3D Visual Enterprise Author where improper memory management allows a specially crafted Iges Part and Assembly (.igs, .iges) file to cause the application to crash. When such files from untrusted sources are opened, it results in temporary unavailability of the application until a restart occurs. Users should exercise caution when handling files from unknown sources to mitigate this risk.

Affected Version(s)

SAP 3D Visual Enterprise Author 9

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.