XML Injection Vulnerability in SAP BusinessObjects BI Platform
CVE-2020-26831
9.6CRITICAL
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 9 December 2020
Summary
The vulnerability in SAP BusinessObjects BI Platform affects versions 4.1, 4.2, and 4.3, where insufficient validation of uploaded XML entities during Crystal Report generation can be exploited. An attacker with basic privileges may inject arbitrary XML entities, potentially leading to serious consequences such as internal file disclosures, exposure of internal directories, Server-Side Request Forgery (SSRF), and denial-of-service (DoS) conditions.
Affected Version(s)
SAP BusinessObjects BI Platform (Crystal Report) < 4.1 < 4.1
SAP BusinessObjects BI Platform (Crystal Report) < 4.2 < 4.2
SAP BusinessObjects BI Platform (Crystal Report) < 4.3 < 4.3
References
CVSS V3.1
Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved