CVE-2022-35171

MEDIUM

SAP 3D Visual Enterprise Viewer - Denial of Service via Malformed JPEG 2000 File

Title source: llm
STIX 2.1

Description

When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/3220746

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 34.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-20
Status published
Products (1)
sap/3d_visual_enterprise_viewer 9
Published Jul 12, 2022
Tracked Since Feb 18, 2026