CVE-2023-37483

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
08/08/2023
Last modified:
28/09/2024

Description

SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:powerdesigner:16.7:*:*:*:*:*:*:*