Multiple vulnerabilities in SAP 3D Visual Enterprise Viewer

Published: 2020-09-10


Risk
High
Patch available
YES
Number of vulnerabilities
38
CVE ID
CVE-2020-6322CVE-2020-6334CVE-2020-6335CVE-2020-6314CVE-2020-6359CVE-2020-6344CVE-2020-6340CVE-2020-6336CVE-2020-6338CVE-2020-6353CVE-2020-6331CVE-2020-6329CVE-2020-6354CVE-2020-6345CVE-2020-6355CVE-2020-6342CVE-2020-6321CVE-2020-6357CVE-2020-6332CVE-2020-6337CVE-2020-6327CVE-2020-6361CVE-2020-6330CVE-2020-6333CVE-2020-6346CVE-2020-6350CVE-2020-6339CVE-2020-6356CVE-2020-6360CVE-2020-6328CVE-2020-6347CVE-2020-6341CVE-2020-6343CVE-2020-6351CVE-2020-6352CVE-2020-6358CVE-2020-6348CVE-2020-6349
CWE ID
CWE-125CWE-416CWE-787CWE-822CWE-121CWE-119CWE-190CWE-122
Exploitation vector
Network
Public exploit
N/A
Vulnerable softwareSubscribe
SAP 3D Visual Enterprise ViewerClient/Desktop applications / Office applications
Vendor
SAP

Security Advisory


13) Use-after-free


Risk: High


CVSSv3: 7.7 [CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C] [PCI]


CVE-ID: CVE-2020-6354


CWE-ID: CWE-416 - Use After Free


Exploit availability: No


Description

The vulnerability allows a remote attacker to compromise vulnerable system.


The vulnerability exists due to a ..

Support the originator by clicking the read the rest link below.