PT-2020-19089 · Sap · Sap 3D Visual Enterprise Viewer
Published
2020-10-19
·
Updated
2020-10-22
·
CVE-2020-6315
CVSS v3.1
5.7
Medium
| Vector | AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SAP 3D Visual Enterprise Viewer version 9
Description
The issue allows an attacker to send a manipulated file to the victim, potentially leading to the leakage of sensitive information when the victim loads the malicious file into the viewer. This can result in information disclosure.
Recommendations
For SAP 3D Visual Enterprise Viewer version 9, consider avoiding the use of malicious or untrusted files until a fix is available. As a temporary workaround, restrict the loading of external files into the viewer to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap 3D Visual Enterprise Viewer