First published: Wed Jul 14 2021(Updated: )
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes out of bounds write and causes the application to crash and becoming temporarily unavailable until the user restarts the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP 3D Visual Enterprise Viewer | =9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-33681.
The severity of CVE-2021-33681 vulnerability is medium with a CVSS score of 6.5.
SAP 3D Visual Enterprise Viewer version 9 becomes temporarily unavailable due to an out of bounds write caused by opening a manipulated CGM file received from untrusted sources, which crashes the application.
To fix the vulnerability, upgrade SAP 3D Visual Enterprise Viewer version 9 to a patched version provided by SAP.
The Common Weakness Enumeration (CWE) ID associated with this vulnerability is CWE-787.