CVE-2022-22539: Input Validation
When a user opens a manipulated JPEG file format (.jpg, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-22539?
CVE-2022-22539 is a vulnerability that occurs when a user opens a manipulated JPEG file format (.jpg, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, causing the application to crash and become temporarily unavailable until restart.
How does CVE-2022-22539 affect SAP 3D Visual Enterprise Viewer?
CVE-2022-22539 affects SAP 3D Visual Enterprise Viewer version 9.0, causing the application to crash and become temporarily unavailable when a user opens a manipulated JPEG file format (.jpg, 2d.x3d) from untrusted sources.
What is the severity of CVE-2022-22539?
CVE-2022-22539 has a severity rating of medium with a score of 6.5.
How can I fix CVE-2022-22539?
To fix CVE-2022-22539, it is recommended to update SAP 3D Visual Enterprise Viewer to a version that has addressed the vulnerability. Refer to the SAP Security Note 3134684 for more information.
What is the Common Weakness Enumeration (CWE) ID of CVE-2022-22539?
The CWE ID of CVE-2022-22539 is CWE-20, which refers to Improper Input Validation.