CVE-2022-39803: Buffer Overflow
Due to lack of proper memory management, when a victim opens a manipulated ACIS Part and Assembly (.sat, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-39803.
What is the severity of CVE-2022-39803?
The severity of CVE-2022-39803 is high with a CVSS score of 7.8.
Which SAP product is affected by CVE-2022-39803?
CVE-2022-39803 affects SAP 3D Visual Enterprise Author version 9.
How can CVE-2022-39803 be exploited?
CVE-2022-39803 can be exploited by opening a manipulated ACIS Part and Assembly (.sat, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author version 9, which can trigger a remote code execution.
Are there any fixes or patches available for CVE-2022-39803?
Please refer to the following SAP notes and documents for information on fixes and patches for CVE-2022-39803: - SAP Note: 3245929 - Document: https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html