CVE-2023-37483: Improper Access Control Vulnerabilities in SAP PowerDesigner
Published Aug 8, 2023
·Updated
SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy.
Affected Software
1 affected component
SAP PowerDesigner=16.7
Event History
Aug 8, 2023
CVE Published
via MITRE·12:39 AM
Data Sourced
via MITRE·12:39 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-37483?
CVE-2023-37483 is a vulnerability in SAP PowerDesigner version 16.7 that allows an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy.
2
How severe is CVE-2023-37483?
CVE-2023-37483 has a severity score of 9.8, which is considered critical.
3
What is the affected software for CVE-2023-37483?
The affected software for CVE-2023-37483 is SAP PowerDesigner version 16.7.
4
How can an attacker exploit CVE-2023-37483?
An unauthenticated attacker can exploit CVE-2023-37483 by running arbitrary queries against the back-end database via Proxy.
5
Is there a fix for CVE-2023-37483?
Yes, it is recommended to update to a fixed version of SAP PowerDesigner to mitigate CVE-2023-37483.