SAP security note 2560132, "[CVE-2018-2406] Unquoted windows search path vulnerability in Crystal Reports Server, OEM Edition", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Unquoted Windows search path vulnerability in Crystal Reports Server, OEM Edition (CRSE) startup path.
Solution
This issue is fixed in the patches listed below. For Business Intelligence Platform maintenance schedule and strategy, see Knowledge Base Article 2144559.
CVSS
Score 5.3 Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
References
Affected components
- ENTERPRISE 4.0
- ENTERPRISE 410
- ENTERPRISE 420
- ENTERPRISE 430
- CRYSTAL REPORT SERVER EMBED 41
- CRYSTAL REPORT SERVER EMBED 42
- CRYSTAL REPORT SERVER EMBED 43
Full note on SAP: SAP Support Launchpad note 2560132
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



