CVE-2020-6330
published 2020-09-09CVE-2020-6330: SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated 3DM file received from untrusted sources which results in crashing of the…
PriorityP418medium4.3CVSS 3.1
AVNACLPRNUIRSUCNINAL
EPSS
1.62%
73.3th percentile
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated 3DM file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | 3d_visual_enterprise_viewer | — | — |
| sap_se | sap_3d_visual_enterprise_viewer | < 9 | 9 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Keycloak vulnerable to Improper Certificate Validation
ghsa·2022-08-24
CVE-2020-35509 [MEDIUM] CWE-20 Keycloak vulnerable to Improper Certificate Validation
Keycloak vulnerable to Improper Certificate Validation
keycloak accepts an expired certificate by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.
This issue was partially fixed in version [13.0.1](https://github.com/keycloak/keycloak/pull/6330) and more completely fixed in version [14.0.0](https://github.com/keycloak/keycloak/pull/8067).
GHSA
GHSA-f4xr-xwq3-38fv: SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated 3DM file received from untrusted sources which results in crashing of
ghsa_unreviewed·2022-05-24
CVE-2020-6330 [MEDIUM] CWE-125 GHSA-f4xr-xwq3-38fv: SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated 3DM file received from untrusted sources which results in crashing of
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated 3DM file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://launchpad.support.sap.com/#/notes/2960815https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700https://www.zerodayinitiative.com/advisories/ZDI-20-1135/https://launchpad.support.sap.com/#/notes/2960815https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700https://www.zerodayinitiative.com/advisories/ZDI-20-1135/
2020-09-09
Published