CVE-2023-37483
CRITICALSAP PowerDesigner 16.7 - Unauthenticated Arbitrary Database Query Execution via Proxy
Title source: llmDescription
SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy.
References (2)
Core 2
Core References
Permissions Required
https://me.sap.com/notes/3341460
Scores
CVSS v3
9.8
EPSS
0.0073
EPSS Percentile
72.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-306
Status
published
Products (1)
sap/powerdesigner
16.7
Published
Aug 08, 2023
Tracked Since
Feb 18, 2026