XML Injection Vulnerability in SAP BusinessObjects BI Platform
CVE-2020-26831

9.6CRITICAL

Key Information:

Vendor
SAP
Vendor
CVE Published:
9 December 2020

Summary

The vulnerability in SAP BusinessObjects BI Platform affects versions 4.1, 4.2, and 4.3, where insufficient validation of uploaded XML entities during Crystal Report generation can be exploited. An attacker with basic privileges may inject arbitrary XML entities, potentially leading to serious consequences such as internal file disclosures, exposure of internal directories, Server-Side Request Forgery (SSRF), and denial-of-service (DoS) conditions.

Affected Version(s)

SAP BusinessObjects BI Platform (Crystal Report) < 4.1 < 4.1

SAP BusinessObjects BI Platform (Crystal Report) < 4.2 < 4.2

SAP BusinessObjects BI Platform (Crystal Report) < 4.3 < 4.3

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.