SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Reports for VS version 2010, allows an attacker with basic authorization to perform deserialization attack in the application, leading to service interruptions and denial of service and unauthorized execution of arbitrary commands, leading to Deserialization of Untrusted Data.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/2863731 | Permissions Required Vendor Advisory |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=544214202 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-04-14 12:15
Updated : 2020-04-15 09:23
NVD link : CVE-2020-6219
Mitre link : CVE-2020-6219
JSON object : View
CWE
CWE-502
Deserialization of Untrusted Data
Products Affected
sap
- businessobjects_business_intelligence_platform
- crystal_reports_for_visual_studio