CVE-2023-40621
12.09.2023, 03:15
SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecting user, to have it executed by the application on behalf of the user. The application has a security option to disable or prompt users before untrusted scripts are executed, but this is not set as default.
Vendor | Product | Version |
---|---|---|
sap | powerdesigner | 16.7 |
𝑥
= Vulnerable software versions