CVE-2022-41192

HIGH

SAP 3D Visual Enterprise Viewer <9 - Use After Free

Title source: llm
STIX 2.1

Description

Due to lack of proper memory management, when a victim opens manipulated Jupiter Tesselation (.jt, JTReader.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

Scores

CVSS v3 7.8
EPSS 0.0013
EPSS Percentile 32.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (1)
sap/3d_visual_enterprise_viewer < 9.0
Published Oct 11, 2022
Tracked Since Feb 18, 2026