CVE-2022-41188

HIGH

SAP 3D Visual Enterprise Viewer <9 - Memory Corruption

Title source: llm
STIX 2.1

Description

Due to lack of proper memory management, when a victim opens manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

Scores

CVSS v3 7.8
EPSS 0.0013
EPSS Percentile 32.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (1)
sap/3d_visual_enterprise_viewer < 9.0
Published Oct 11, 2022
Tracked Since Feb 18, 2026