SAP security note 1999142, "Potential remote code execution in SAP CrystalReports". Below are the symptom and SAP recommended solution.
Description
Symptom
UPDATE 20th June 2018: This note has been re-released, with updated ‘Support Packages & Patches’ and CVSS information.
UPDATE 11th June 2018: This note has been re-released, updating the CVSS from v2 to v3.
An attacker can exploit SAP CrystalReports to enable them to inject code into the working memory that is subsequently executed by the application.
Solution
The issue has been fixed in the following SAP BusinessObjects Enterprise and SAP Crystal Reports for Microsoft Visual Studio releases. Please apply the below listed packages:
- SAP BusinessObjects Enterprise 4.0 SP09 Patch5
- SAP BusinessObjects Enterprise 4.1 SP04 Patch1
- SAP Crystal Reports, version for Microsoft Visual Studio SP23
Reason and prerequisites
A buffer overflow vulnerability exists in SAP CrystalReports. This enables an attacker to inject code into the working memory that is subsequently executed by the application. It can also be used to cause a general fault in the product, causing the product to terminate.
CVSS
Score 6.6 Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Full note on SAP: SAP Support Launchpad note 1999142
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



