SAP security note 2687663, "[CVE-2019-0285] Information Disclosure in SAP Crystal Reports", is a program error note released on 09.04.2019. Below are the symptom and the SAP recommended solution.
Description
Symptom
Under certain conditions, the SAP Crystal Reports .NET SDK WebForm Viewer discloses sensitive database information including credentials, which are otherwise restricted.
Some well-known impacts of Information Disclosure are:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
The Crystal Reports .NET SDK Webform Viewer no longer allows such disclosure of sensitive database information. This issue is fixed in the patches listed below.
Reason and prerequisites
Environment: SAP Crystal Reports, version for Microsoft Visual Studio SP23.
CVSS
Score 7.5 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Full note on SAP: SAP Support Launchpad note 2687663
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
