Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-41370 | SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy. |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 28 Sep 2024 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Sat, 28 Sep 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy. | SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy. |
| Weaknesses | CWE-306 |
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-10-10T19:00:59.714Z
Reserved: 2023-07-06T14:57:18.506Z
Link: CVE-2023-37483
Updated: 2024-08-02T17:16:30.206Z
Status : Modified
Published: 2023-08-08T01:15:17.313
Modified: 2024-11-21T08:11:48.373
Link: CVE-2023-37483
No data.
OpenCVE Enrichment
No data.
EUVD