First published: Wed Sep 09 2020(Updated: )
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated BMP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP 3D Visual Enterprise Viewer | =9 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6356 has a medium severity rating due to its potential to crash the application.
To mitigate CVE-2020-6356, avoid opening manipulated BMP files from untrusted sources and consider updating to the latest version of SAP 3D Visual Enterprise Viewer.
CVE-2020-6356 specifically affects SAP 3D Visual Enterprise Viewer version 9.
CVE-2020-6356 facilitates application crashes through improper input validation of BMP files.
A potential workaround for CVE-2020-6356 is to carefully screen BMP files received from untrusted sources before opening them.