Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-26817 Improper input validation in Visual Enterprise Viewer, SAP security note 2985094

SAP Note 2985094

SAP security note 2985094, "[CVE-2020-26817] Improper input validation in Visual Enterprise Viewer". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

When a user opens manipulated HPGL-files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable until it is restarted.

Solution

This issue is resolved in the patch listed in the "Support Packages & Patches" section below.

Refer to SAP Note 2982077 for release information about SAP 3D Visual Enterprise Viewer 9.0 FP09 MP4.

Reason and prerequisites

The vulnerability arises from insufficient input validation when opening specific file formats in the SAP 3D Visual Enterprise Viewer.

CVSS

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

References

Affected components

  • VE_VIEWER_COMPLETE: Version 9

Full note on SAP: SAP Support Launchpad note 2985094

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More