The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including credentials which can be misused by the attacker.
References
Link | Resource |
---|---|
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=517899114 | Vendor Advisory |
https://launchpad.support.sap.com/#/notes/2687663 | Permissions Required Vendor Advisory |
http://packetstormsecurity.com/files/153471/SAP-Crystal-Reports-Information-Disclosure.html |
Configurations
Information
Published : 2019-04-10 14:29
Updated : 2020-08-24 10:37
NVD link : CVE-2019-0285
Mitre link : CVE-2019-0285
JSON object : View
CWE
CWE-312
Cleartext Storage of Sensitive Information
Products Affected
sap
- crystal_reports