Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6219 Deserialization of Untrusted Data in SAP Business Objects Business Intelligence Platform (CR .Net SDK WebForm Viewer), SAP security note 2863731

SAP Note 2863731

SAP security note 2863731, "[CVE-2020-6219] Deserialization of Untrusted Data in SAP Business Objects Business Intelligence Platform (CR .Net SDK WebForm Viewer)", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Crystal Reports .Net SDK WebForm Viewer allows an attacker with basic authorization to perform a deserialization attack in the application, potentially leading to code execution.

  • Availability: Total loss of service availability, enabling full denial of access to resources in the impacted component.
  • Integrity: Unauthorized execution of arbitrary commands.

Solution

The data transmission between the server and client has been encrypted to ensure secure information transmission, preventing tampering during deserialization. This issue is addressed in the patches listed below.

CVSS

Score 9.1 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H

Affected components

  • Business intelligence solutions > Reporting, analysis, and dashboards > SAP Crystal Reports Viewer (BI-RA-CRV)
  • ENTERPRISE 410, 420, 430; CRYSTAL REPORTS FOR VS 2010

Full note on SAP: SAP Support Launchpad note 2863731

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More