ID

VAR-201603-0336


TITLE

SAP 3D Visual Enterprise Viewer Memory Error Reference Remote Code Execution Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2016-01563

DESCRIPTION

SAP 3D Visual Enterprise Viewer (VEV) is a suite of software from SAP, Inc. for viewing, scaling, panning and rotating interactive 3D data and playing step-by-step animations. A security vulnerability exists in SAP 3D Visual Enterprise Viewer. Allows an attacker to exploit this vulnerability to execute arbitrary script code in the context of the current process or to cause a denial of service

Trust: 0.72

sources: CNVD: CNVD-2016-01563 // IVD: 18e4e494-1e42-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 18e4e494-1e42-11e6-abef-000c29c66e3d // CNVD: CNVD-2016-01563

AFFECTED PRODUCTS

vendor:sapmodel:3d visual enterprise viewerscope: - version: -

Trust: 0.6

vendor:sapmodel:3d visual enterprise viewerscope:eqversion:*

Trust: 0.2

sources: IVD: 18e4e494-1e42-11e6-abef-000c29c66e3d // CNVD: CNVD-2016-01563

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-01563
value: HIGH

Trust: 0.6

IVD: 18e4e494-1e42-11e6-abef-000c29c66e3d
value: HIGH

Trust: 0.2

CNVD: CNVD-2016-01563
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 18e4e494-1e42-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 18e4e494-1e42-11e6-abef-000c29c66e3d // CNVD: CNVD-2016-01563

TYPE

Code injection

Trust: 0.2

sources: IVD: 18e4e494-1e42-11e6-abef-000c29c66e3d

EXTERNAL IDS

db:CNVDid:CNVD-2016-01563

Trust: 0.8

db:BIDid:83308

Trust: 0.6

db:IVDid:18E4E494-1E42-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 18e4e494-1e42-11e6-abef-000c29c66e3d // CNVD: CNVD-2016-01563

REFERENCES

url:http://www.securityfocus.com/bid/83308

Trust: 0.6

sources: CNVD: CNVD-2016-01563

SOURCES

db:IVDid:18e4e494-1e42-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2016-01563

LAST UPDATE DATE

2022-05-17T01:41:10.325000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-01563date:2016-03-11T00:00:00

SOURCES RELEASE DATE

db:IVDid:18e4e494-1e42-11e6-abef-000c29c66e3ddate:2016-03-11T00:00:00
db:CNVDid:CNVD-2016-01563date:2016-03-11T00:00:00