Description
When a user opens manipulated Scalable Vector Graphics (.SVG) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_misc
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=571343107
Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/3027758
Third Party Advisory, VDB Entry x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-21-306/
Scores
CVSS v3
7.8
EPSS
0.0019
EPSS Percentile
39.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
Status
published
Products (1)
sap/3d_visual_enterprise_viewer
9
Published
Mar 09, 2021
Tracked Since
Feb 18, 2026