CVE-2023-40310

SAP PowerDesignerClient- version 16.7, does not sufficiently validate BPMN2XML document imported from an untrusted source. As a result, URLs ofexternal entities in BPMN2 file, although not used, would be accessedduring import.A successful attack could impact availability of SAP PowerDesignerClient.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
sapCNA
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVEADP
---
---
CISA-ADPADP
---
---