First published: Mon Aug 28 2023(Updated: )
An OS Command Injection vulnerability exists in SIMULIA 3DOrchestrate from Release 3DEXPERIENCE R2021x through Release 3DEXPERIENCE R2023x. A specially crafted HTTP request can lead to arbitrary command execution.
Credit: 3DS.Information-Security@3ds.com 3DS.Information-Security@3ds.com
Affected Software | Affected Version | How to fix |
---|---|---|
3ds 3dexperience | =r2021x | |
3ds 3dexperience | =r2022x | |
3ds 3dexperience | =r2023x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1997 is an OS Command Injection vulnerability in SIMULIA 3DOrchestrate from Release 3DEXPERIENCE R2021x through Release 3DEXPERIENCE R2023x.
CVE-2023-1997 has a severity rating of 8.8 (high).
To exploit CVE-2023-1997, an attacker would need to send a specially crafted HTTP request that can lead to arbitrary command execution.
The following versions of SIMULIA 3DOrchestrate are affected: Release 3DEXPERIENCE R2021x, R2022x, and R2023x.
To fix CVE-2023-1997, it is recommended to apply the latest security patches provided by the vendor.