First published: Wed Jul 14 2021(Updated: )
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes buffer overflow and causes the application to crash and becoming temporarily unavailable until the user restarts the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP 3D Visual Enterprise Viewer | =9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-33680.
The severity of CVE-2021-33680 is medium with a CVSS score of 6.5.
CVE-2021-33680 allows a user to open manipulated CGM files from untrusted sources, causing a buffer overflow and crashing the application.
To fix CVE-2021-33680, update SAP 3D Visual Enterprise Viewer to a version that has a fix for the vulnerability.
Yes, you can find more information about CVE-2021-33680 at the following references: [link1](https://launchpad.support.sap.com/#/notes/3067890) and [link2](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=580617506).