CVE-2021-21449
Published on: 01/12/2021 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:28:57 PM UTC
Certain versions of 3d Visual Enterprise Viewer from Sap contain the following vulnerability:
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
- CVE-2021-21449 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
SAP SE - SAP 3D Visual Enterprise Viewer version 9
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6.8 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
SAP Security Patch Day – January 2021 - Product Security Response at SAP - Community Wiki | Vendor Advisory wiki.scn.sap.com text/html |
![]() |
No Description Provided | Permissions Required launchpad.support.sap.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Sap | 3d Visual Enterprise Viewer | 9 | All | All | All |
Application | Sap | 3d Visual Enterprise Viewer | 9 | All | All | All |
- cpe:2.3:a:sap:3d_visual_enterprise_viewer:9:*:*:*:*:*:*:*:
- cpe:2.3:a:sap:3d_visual_enterprise_viewer:9:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-21449の問題は証明書とか署名ベースのトークン認証に対してはかなりの脅威にはなるけど、こういう脆弱性が見つかったときの事を考えるとよくある「パスワードレス認証」は一撃で死亡するリスクがあるんですよ。 | 2022-04-21 12:18:08 |