CVE-2023-40310CWE-112

Missing XML Validation vulnerability in SAP PowerDesigner Client BPMN2 import

Medium · published October 10, 2023

CVSS v3.1
6.5
EPSS
1%
Percentile
54.2
In the wild
Unconfirmed
What it is

SAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted source. As a result, URLs of external entities in BPMN2 file, although not used, would be accessed during import. A successful attack could impact availability of SAP PowerDesigner Client.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00800 · 54.2th percentile
Weakness
CWE-112 · Missing XML Validation
Published
2023-10-10T01:35Z
EPSS history
Timeline
  • 10 OCT 01:35Z
    Missing XML Validation vulnerability in SAP PowerDesigner Client BPMN2 import
    cvelistv5