CVE-2023-40310
SAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted source. As a result, URLs of external entities in BPMN2 file, although not used, would be accessed during import. A successful attack could impact availability of SAP PowerDesigner Client.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS probability
- 0.40%
- CWE
- CWE-112
- Published
- 2023-10-10
- Last modified
- 2026-03-13
Affected products
- SAP_SE SAP PowerDesigner Client
Weakness type
Related vulnerabilities
- CVE-2026-1190 — Org.keycloak/keycloak-services: keycloak saml brokering: response delay due to unchecked notonorafter in subjectconfirmationdata
- CVE-2021-27780 — HCL BigFix Mobile / Modern Client Management is vulnerable to unauthenticated XML interaction
- CVE-2022-28213 — When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform -...
- CVE-2021-1359 — Cisco Web Security Appliance Privilege Escalation Vulnerability
- CVE-2020-27282 — In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an XML validation vulnerability in...
- CVE-2020-1975 — Missing XML Validation in PAN-OS Web Interface