CVE-2022-26109: Input Validation
When a user opens a manipulated Portable Document Format (.pdf, PDFView.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-26109?
CVE-2022-26109 is a vulnerability in SAP 3D Visual Enterprise Viewer version 9.0 that allows for a denial of service attack when a user opens a manipulated PDF file.
How does CVE-2022-26109 affect SAP 3D Visual Enterprise Viewer?
CVE-2022-26109 affects SAP 3D Visual Enterprise Viewer version 9.0 by causing the application to crash and become temporarily unavailable when a manipulated PDF file is opened.
What is the severity of CVE-2022-26109?
CVE-2022-26109 has a severity rating of 6.5 (medium).
How can I fix CVE-2022-26109?
To fix CVE-2022-26109, update SAP 3D Visual Enterprise Viewer to a version that has the vulnerability patched.
Where can I find more information about CVE-2022-26109?
More information about CVE-2022-26109 can be found in the SAP support note 3143437 and the SAP document linked in the references.