Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2406 Unquoted windows search path vulnerability in Crystal Reports Server, OEM Edition, SAP security note 2560132

SAP Note 2560132

SAP security note 2560132, "[CVE-2018-2406] Unquoted windows search path vulnerability in Crystal Reports Server, OEM Edition", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Unquoted Windows search path vulnerability in Crystal Reports Server, OEM Edition (CRSE) startup path.

Solution

This issue is fixed in the patches listed below. For Business Intelligence Platform maintenance schedule and strategy, see Knowledge Base Article 2144559.

CVSS

Score 5.3 Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

References

Affected components

  • ENTERPRISE 4.0
  • ENTERPRISE 410
  • ENTERPRISE 420
  • ENTERPRISE 430
  • CRYSTAL REPORT SERVER EMBED 41
  • CRYSTAL REPORT SERVER EMBED 42
  • CRYSTAL REPORT SERVER EMBED 43

Full note on SAP: SAP Support Launchpad note 2560132

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More