Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-26831 Missing XML Validation in SAP BusinessObjects Business Intelligence Platform (Crystal Report), SAP security note 2989075

SAP Note 2989075

SAP security note 2989075, “CVE-2020-26831 – Missing XML Validation in SAP BusinessObjects Business Intelligence Platform”. Below are the symptom and the SAP recommended solution.

ComponentBusiness Intelligence Solutions > Reporting, Analysis, and Dashboards > Crystal Reports Designer or Business View Manager > Viewers (BI-RA-CR-VW)

Description

Symptom

Crystal Report does not sufficiently validate uploaded XML entities. An attacker with basic privileges can inject arbitrary XML entities, leading to internal file disclosure, internal directories disclosure, Server Side Request Forgery (SSRF), and denial-of-service (DoS).

Solution

To address this vulnerability, apply the Support Package referenced by this SAP Note. The correction ensures that the values of specific input parameters are ignored, preventing the injection of malicious XML entities.

CVSS

Score 9.6 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H

Full note on SAP: SAP Support Launchpad note 2989075

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More