Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0285 Information Disclosure in SAP Crystal Reports, SAP security note 2687663

SAP Note 2687663SAP Security NoteHigh priority

SAP security note 2687663, "[CVE-2019-0285] Information Disclosure in SAP Crystal Reports", is a program error note released on 09.04.2019. Below are the symptom and the SAP recommended solution.

ComponentBI-RA-CRV (Business intelligence solutions > Reporting, analysis, and dashboards > SAP Crystal Reports Viewer)
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on09.04.2019
LanguageEnglish

Description

Symptom

Under certain conditions, the SAP Crystal Reports .NET SDK WebForm Viewer discloses sensitive database information including credentials, which are otherwise restricted.

Some well-known impacts of Information Disclosure are:

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

The Crystal Reports .NET SDK Webform Viewer no longer allows such disclosure of sensitive database information. This issue is fixed in the patches listed below.

Reason and prerequisites

Environment: SAP Crystal Reports, version for Microsoft Visual Studio SP23.

CVSS

Score 7.5 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2687663

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More