First published: Tue Aug 08 2023(Updated: )
SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy.
Credit: cna@sap.com cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP PowerDesigner | =16.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37483 is a vulnerability in SAP PowerDesigner version 16.7 that allows an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy.
CVE-2023-37483 has a severity score of 9.8, which is considered critical.
The affected software for CVE-2023-37483 is SAP PowerDesigner version 16.7.
An unauthenticated attacker can exploit CVE-2023-37483 by running arbitrary queries against the back-end database via Proxy.
Yes, it is recommended to update to a fixed version of SAP PowerDesigner to mitigate CVE-2023-37483.