PT-2020-19089 · Sap · Sap 3D Visual Enterprise Viewer

Published

2020-10-19

·

Updated

2020-10-22

·

CVE-2020-6315

CVSS v3.1

5.7

Medium

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP 3D Visual Enterprise Viewer version 9
Description The issue allows an attacker to send a manipulated file to the victim, potentially leading to the leakage of sensitive information when the victim loads the malicious file into the viewer. This can result in information disclosure.
Recommendations For SAP 3D Visual Enterprise Viewer version 9, consider avoiding the use of malicious or untrusted files until a fix is available. As a temporary workaround, restrict the loading of external files into the viewer to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-6315
ZDI-20-1265

Affected Products

Sap 3D Visual Enterprise Viewer