Description
SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecting user, to have it executed by the application on behalf of the user. The application has a security option to disable or prompt users before untrusted scripts are executed, but this is not set as default.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-45177 | SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecting user, to have it executed by the application on behalf of the user. The application has a security option to disable or prompt users before untrusted scripts are executed, but this is not set as default. |
References
History
Wed, 25 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-09-25T15:25:02.097Z
Reserved: 2023-08-17T18:10:44.965Z
Link: CVE-2023-40621
Updated: 2024-08-02T18:38:50.977Z
Status : Modified
Published: 2023-09-12T03:15:12.627
Modified: 2024-11-21T08:19:50.317
Link: CVE-2023-40621
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD