Advisory
On 08.11.2022 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within SAP 3D Visual Enterprise .
SAP Note 3263436 addresses "[CVE-2022-41211] Arbitrary Code Execution vulnerability in SAP 3D Visual Enterprise Author and SAP 3D Visual Enterprise Viewer" to prevent code injection with a high risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance, the team suggests.
Risk specification
SAP 3D Visual Enterprise Viewer does not properly validate inputs of certain file types, allowing an unauthenticated user to open manipulated files from untrusted sources, resulting in vulnerability to code injection.Solution
SAP 3D Visual Enterprise Viewer now properly validates the input files.
- 9.9 [CVE-2023-0022] Code Injection vulnerability in SAP BusinessObjects Business Intelligence platform (Analysis edition for OLAP)
- 8.8 [CVE-2023-27893] Arbitrary Code Execution in SAP Solution Manager and ABAP managed systems (ST-PI)
- 6.4 [CVE-2023-0012] Local Privilege Escalation in SAP Host Agent (Windows)
- 5.4 [CVE-2023-23851] Unrestricted File Upload in SAP Business Planning and Consolidation