PT-2023-4252 · Sap · Sap Sqla For Powerdesigner+2

Published

2023-08-08

·

Updated

2023-08-15

·

CVE-2023-36923

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03
Description The issue is related to the integration of a malicious library due to incorrect code generation management in the SAP SQL Anywhere tool for SAP PowerDesigner. This could allow an attacker with local access to the system to place a malicious library that can be executed by the application, potentially giving the attacker control over the application's behavior.
Recommendations For SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, consider restricting access to the system to prevent an attacker from placing a malicious library until a fix is available. As a temporary workaround, review and monitor the application's behavior closely for any signs of malicious activity. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2023-04567
CVE-2023-36923

Affected Products

Sap Powerdesigner
Sap Sql Anywhere
Sap Sqla For Powerdesigner