SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the behaviour of the application, leading to Remote Code Execution. Although the mode of attack is only Local, multiple applications can be impacted as a result of the vulnerability.
References
Link | Resource |
---|---|
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305 | Vendor Advisory |
https://launchpad.support.sap.com/#/notes/2861301 | Permissions Required |
https://www.zerodayinitiative.com/advisories/ZDI-20-291/ | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-03-10 14:15
Updated : 2021-07-21 04:39
NVD link : CVE-2020-6208
Mitre link : CVE-2020-6208
JSON object : View
CWE
CWE-416
Use After Free
Products Affected
sap
- crystal_reports