PT-2023-27544 · Sap · Sap Powerdesigner Client

Published

2023-09-11

·

Updated

2023-09-13

·

CVE-2023-40621

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions SAP PowerDesigner Client version 16.7
Description The issue allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecting user, to have it executed by the application on behalf of the user. The application has a security option to disable or prompt users before untrusted scripts are executed, but this is not set as default.
Recommendations For SAP PowerDesigner Client version 16.7, consider enabling the security option to disable or prompt users before untrusted scripts are executed to minimize the risk of exploitation. As a temporary workaround, consider disabling the execution of VBScript code in documents until a patch is available.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2023-40621

Affected Products

Sap Powerdesigner Client