First published: Wed Sep 09 2020(Updated: )
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated BMP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP 3D Visual Enterprise Viewer | =9 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6350 has been assessed with a moderate severity rating due to the potential for application crashes.
To mitigate CVE-2020-6350, ensure that your SAP 3D Visual Enterprise Viewer is updated to the latest security patches provided by SAP.
CVE-2020-6350 can be exploited by opening manipulated BMP files from untrusted sources.
The impact of CVE-2020-6350 includes application crashes and temporary unavailability until the application is restarted.
While updating the software reduces risk, it's still advisable to only open BMP files from trusted sources to mitigate potential exploitation.