SAP security note 2989075, “CVE-2020-26831 – Missing XML Validation in SAP BusinessObjects Business Intelligence Platform”. Below are the symptom and the SAP recommended solution.
Description
Symptom
Crystal Report does not sufficiently validate uploaded XML entities. An attacker with basic privileges can inject arbitrary XML entities, leading to internal file disclosure, internal directories disclosure, Server Side Request Forgery (SSRF), and denial-of-service (DoS).
Solution
To address this vulnerability, apply the Support Package referenced by this SAP Note. The correction ensures that the values of specific input parameters are ignored, preventing the injection of malicious XML entities.
CVSS
Score 9.6 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H
Full note on SAP: SAP Support Launchpad note 2989075
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
