CVE-2023-36923 is a critical vulnerability affecting SAP SQLA for PowerDesigner 17, bundled with SAP PowerDesigner 16.7 SP06 PL03, allowing a local attacker to execute arbitrary code by placing a malicious library. With a CVSS score of 7.8 (High), this vulnerability requires local access and low privileges but can lead to complete compromise of confidentiality, integrity, and availability. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, indicating no active exploitation. While community discussion and media coverage are minimal, the potential for high impact necessitates prompt patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.7CPE matchmatch criteria | cpe:2.3:a:sap:powerdesigner:16.7:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.