Known Vulnerabilities for Powerdesigner by Sap
Listed below are 5 of the newest known vulnerabilities associated with "Powerdesigner" by "Sap".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-40621 json | SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it... | 6.3 - MEDIUM | 2023-09-12 | 2023-09-13 |
| CVE-2023-40310 json | SAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted sour... | 7.5 - HIGH | 2023-10-10 | 2023-10-11 |
| CVE-2023-37484 json | SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user provided ... | 5.3 - MEDIUM | 2023-08-08 | 2023-08-09 |
| CVE-2023-37483 json | SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary ... | 9.8 - CRITICAL | 2023-08-08 | 2023-08-09 |
| CVE-2023-36923 json | SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, allows an attacker with local access to the sys... | 7.8 - HIGH | 2023-08-08 | 2023-08-15 |