NA

CVE-2023-40310

Published: 10/10/2023 Updated: 11/10/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

SAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted source. As a result, URLs of external entities in BPMN2 file, although not used, would be accessed during import. A successful attack could impact availability of SAP PowerDesigner Client.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap powerdesigner 16.7