Code Injection vulnerability in SAP PowerDesigner
CVE-2023-36923
7.8HIGH
Summary
A vulnerability in SAP SQLA for PowerDesigner 17 and SAP PowerDesigner 16.7 SP06 PL03 enables an attacker with local access to introduce a malicious library into the system. Once executed by the application, this can alter the application’s behavior, potentially compromising security and functionality. Users are advised to apply necessary mitigations to prevent unauthorized library placements.
Affected Version(s)
SAP PowerDesigner 16.7
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved