Code Injection Vulnerability in SAP BusinessObjects BI Suite and Crystal Reports
CVE-2018-2427
8.8HIGH
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 10 July 2018
Summary
A code injection vulnerability exists in SAP BusinessObjects Business Intelligence Suite 4.10 and 4.20, as well as SAP Crystal Reports for Visual Studio .NET (Version 2010). This flaw allows attackers to execute unauthorized code in the affected applications, resulting in potential manipulation of application behavior. Such exploitation could lead to significant security breaches, enabling attackers to gain control over sensitive data and system operations.
Affected Version(s)
SAP BusinessObjects Business Intelligence Suite = 4.10 = 4.10
SAP BusinessObjects Business Intelligence Suite = 4.20 = 4.20
SAP Crystal Reports = version for Visual Studio .NET, Version 2010
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved