CVE-2020-26831
9.6CRITICAL
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 9 December 2020
Summary
SAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML entities during crystal report generation due to missing XML validation, An attacker with basic privileges can inject some arbitrary XML entities leading to internal file disclosure, internal directories disclosure, Server-Side Request Forgery (SSRF) and denial-of-service (DoS).
Affected Version(s)
SAP BusinessObjects BI Platform (Crystal Report) < 4.1 < 4.1
SAP BusinessObjects BI Platform (Crystal Report) < 4.2 < 4.2
SAP BusinessObjects BI Platform (Crystal Report) < 4.3 < 4.3
References
CVSS V3.1
Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved