VYPR

PowerDesigner Client

by SAP

CVEs (2)

  • CVE-2023-40310MedOct 10, 2023
    risk 0.42cvss 6.5epss 0.01

    SAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted source. As a result, URLs of external entities in BPMN2 file, although not used, would be accessed during import. A successful attack could impact…

  • CVE-2023-40621MedSep 12, 2023
    risk 0.41cvss 6.3epss 0.01

    SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecting user, to have it executed by the application on behalf of the user. The application has a security option to disable or prompt…