CVE-2022-41194: Buffer Overflow
Due to lack of proper memory management, when a victim opens a manipulated Encapsulated Postscript (.eps, ai.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-41194.
What is the severity of CVE-2022-41194?
The severity of CVE-2022-41194 is high with a severity value of 7.8.
What software is affected by CVE-2022-41194?
SAP 3D Visual Enterprise Viewer version 9 is affected by CVE-2022-41194.
How can the application crash be triggered?
The application can crash when a victim opens a manipulated Encapsulated Postscript (.eps, ai.x3d) file received from untrusted sources.
Where can I find more information about CVE-2022-41194?
You can find more information about CVE-2022-41194 in the SAP support note: [link] and in the SAP documentation: [link].