CVE-2022-26106: Input Validation
When a user opens a manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-26106?
CVE-2022-26106 is a vulnerability in SAP 3D Visual Enterprise Viewer version 9.0, where opening a manipulated Computer Graphics Metafile (.cgm) received from untrusted sources can cause the application to crash and become temporarily unavailable.
How does CVE-2022-26106 affect SAP 3D Visual Enterprise Viewer?
CVE-2022-26106 affects SAP 3D Visual Enterprise Viewer version 9.0. When a user opens a manipulated Computer Graphics Metafile (.cgm) received from untrusted sources, the application crashes and becomes temporarily unavailable.
What is the severity of CVE-2022-26106?
The severity of CVE-2022-26106 is medium with a CVSS score of 6.5.
How can I fix CVE-2022-26106?
To fix CVE-2022-26106, update SAP 3D Visual Enterprise Viewer to a version that is not affected by this vulnerability.
Where can I find more information about CVE-2022-26106?
You can find more information about CVE-2022-26106 in the SAP Note 3143437 and the SAP Security Advisory document.