Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6208 Remote Code Execution in SAP Business Objects Business Intelligence Platform (Crystal Reports), SAP security note 2861301

SAP Note 2861301

SAP security note 2861301, “[CVE-2020-6208] Remote Code Execution in SAP Business Objects Business Intelligence Platform (Crystal Reports)”. Below are the symptom and SAP recommended solution.

Description

Symptom

UPDATE 14th April 2020: This note has been re-released with updated ‘validity’, and ‘Support Packages & Patches’ information. We added the validity for CRYSTAL REPORTS FOR VS 2010 and SP027 respectively.

Crystal Reports Designer allows an attacker with basic authorization to inject code that can be executed by the application. The attacker could hence control the behavior of the application.

Some well-known impacts of the vulnerability are:

  • Unauthorized execution of arbitrary commands.
  • Sensitive information disclosure.
  • Denial of Service or system crashing.
  • Inserting system commands, writing, deleting, or reading files.

Solution

This issue is fixed in the patches listed in the "Support Packages & Patches" section below. The application has been updated with safer functions and implementations. The "Support Packages & Patches" section will be populated with the relevant patch levels once they are released.

Reason and prerequisites

An attacker needs to upload a file to the platform and have it opened by a user to perform the attack.

CVSS

Score 8.2 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Full note on SAP: SAP Support Launchpad note 2861301

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More