CVE-2023-40310: Missing XML Validation vulnerability in SAP PowerDesigner Client BPMN2 import
SAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted source. As a result, URLs of external entities in BPMN2 file, although not used, would be accessed during import. A successful attack could impact availability of SAP PowerDesigner Client.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-40310?
The severity of CVE-2023-40310 is high with a CVSS score of 7.5.
What is the affected software version of CVE-2023-40310?
The affected software version of CVE-2023-40310 is SAP PowerDesigner Client version 16.7.
How does CVE-2023-40310 impact SAP PowerDesigner Client?
CVE-2023-40310 allows an attacker to impact the availability of SAP PowerDesigner Client.
How can I fix CVE-2023-40310?
To fix CVE-2023-40310, it is recommended to update SAP PowerDesigner Client to a version that includes the necessary security patches.
Where can I find more information about CVE-2023-40310?
More information about CVE-2023-40310 can be found in the SAP Note 3357154 and the SAP document provided.