CVE-2022-41202: Buffer Overflow
Due to lack of proper memory management, when a victim opens a manipulated Visual Design Stream (.vds, vds.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-41202.
What is the title of this vulnerability?
The title of this vulnerability is 'Due to lack of proper memory management when a victim opens a manipulated Visual Design Stream (.vds, vds.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow.'
What is the severity keyword for this vulnerability?
The severity keyword for this vulnerability is high.
What is the severity value for this vulnerability?
The severity value for this vulnerability is 7.8.
What is the affected software for this vulnerability?
The affected software for this vulnerability is SAP 3D Visual Enterprise Viewer - version 9.
How can I exploit this vulnerability?
To exploit this vulnerability, you need to manipulate a Visual Design Stream file (.vds, vds.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.
How can I fix this vulnerability?
To fix this vulnerability, update SAP 3D Visual Enterprise Viewer to a version higher than 9.0.
Are there any references for this vulnerability?
Yes, there are references for this vulnerability. You can find them at the following links: [Reference 1](https://launchpad.support.sap.com/#/notes/3245928), [Reference 2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).
What is the associated CWE for this vulnerability?
The associated CWEs for this vulnerability are CWE-119 and CWE-787.