CVE-2023-40621

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
12/09/2023
Last modified:
13/09/2023

Description

SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecting user, to have it executed by the application on behalf of the user. The application has a security option to disable or prompt users before untrusted scripts are executed, but this is not set as default.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:powerdesigner:16.7:*:*:*:*:*:*:*