PT-2023-27544 · Sap · Sap Powerdesigner Client

CVE-2023-40621

·

Publicado

2023-09-11

·

Atualizado

2023-09-13

CVSS v3.1

6.3

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions SAP PowerDesigner Client version 16.7
Description The issue allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecting user, to have it executed by the application on behalf of the user. The application has a security option to disable or prompt users before untrusted scripts are executed, but this is not set as default.
Recommendations For SAP PowerDesigner Client version 16.7, consider enabling the security option to disable or prompt users before untrusted scripts are executed to minimize the risk of exploitation. As a temporary workaround, consider disabling the execution of VBScript code in documents until a patch is available.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-40621

Produtos afetados

Sap Powerdesigner Client