CVE-2020-6208
7.5HIGH
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 10 March 2020
Summary
SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the behaviour of the application, leading to Remote Code Execution. Although the mode of attack is only Local, multiple applications can be impacted as a result of the vulnerability.
Affected Version(s)
SAP Business Objects Business Intelligence Platform (Crystal Reports) < 4.1 < 4.1
SAP Business Objects Business Intelligence Platform (Crystal Reports) < 4.2 < 4.2
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved