First published: Tue Aug 08 2023(Updated: )
SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, allows an attacker with local access to the system, to place a malicious library, that can be executed by the application. An attacker could thereby control the behavior of the application.
Credit: cna@sap.com cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP PowerDesigner | =16.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-36923 is a vulnerability in SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03 that allows an attacker with local access to the system to place a malicious library, which can be executed by the application and control its behavior.
CVE-2023-36923 has a severity rating of 7.8 (High).
CVE-2023-36923 affects SAP PowerDesigner 16.7 SP06 PL03 by allowing an attacker with local access to the system to place a malicious library, which can be executed by the application and control its behavior.
An attacker with local access to the system can exploit CVE-2023-36923 by placing a malicious library that can be executed by SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03.
To mitigate CVE-2023-36923, SAP recommends applying the patches and updates provided in the SAP notes 3341599 and following the recommendations outlined in the SAP security advisory.