CVE-2020-6315

MEDIUM

SAP 3D Visual Enterprise Viewer 9 - Info Disclosure

Title source: llm
STIX 2.1

Description

SAP 3D Visual Enterprise Viewer, version 9, allows an attacker to send certain manipulated file to the victim, which can lead to leakage of sensitive information when the victim loads the malicious file into the VE viewer, leading to Information Disclosure.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2973497

Scores

CVSS v3 5.5
EPSS 0.0016
EPSS Percentile 36.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

Status published
Products (1)
sap/3d_visual_enterprise_viewer 9
Published Oct 20, 2020
Tracked Since Feb 18, 2026