XML Injection Vulnerability in SAP BusinessObjects BI Platform
CVE-2020-26831
9.6CRITICAL
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 9 December 2020
What is CVE-2020-26831?
The vulnerability in SAP BusinessObjects BI Platform affects versions 4.1, 4.2, and 4.3, where insufficient validation of uploaded XML entities during Crystal Report generation can be exploited. An attacker with basic privileges may inject arbitrary XML entities, potentially leading to serious consequences such as internal file disclosures, exposure of internal directories, Server-Side Request Forgery (SSRF), and denial-of-service (DoS) conditions.
Affected Version(s)
SAP BusinessObjects BI Platform (Crystal Report) < 4.1 < 4.1
SAP BusinessObjects BI Platform (Crystal Report) < 4.2 < 4.2
SAP BusinessObjects BI Platform (Crystal Report) < 4.3 < 4.3