SAP security note 2985094, "[CVE-2020-26817] Improper input validation in Visual Enterprise Viewer". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
When a user opens manipulated HPGL-files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable until it is restarted.
Solution
This issue is resolved in the patch listed in the "Support Packages & Patches" section below.
Refer to SAP Note 2982077 for release information about SAP 3D Visual Enterprise Viewer 9.0 FP09 MP4.
Reason and prerequisites
The vulnerability arises from insufficient input validation when opening specific file formats in the SAP 3D Visual Enterprise Viewer.
CVSS
Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
References
Affected components
- VE_VIEWER_COMPLETE: Version 9
Full note on SAP: SAP Support Launchpad note 2985094
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
