Code Injection vulnerability in SAP PowerDesigner Client
Vulnerability Description
SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecting user, to have it executed by the application on behalf of the user. The application has a security option to disable or prompt users before untrusted scripts are executed, but this is not set as default.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-40621
Credits & Attribution
No credits recorded in the NVD database.
References
More from SAP_SE
View All →Affected Vendor
SAP_SE
View all reports →