SAP security note 2861301, “[CVE-2020-6208] Remote Code Execution in SAP Business Objects Business Intelligence Platform (Crystal Reports)”. Below are the symptom and SAP recommended solution.
Description
Symptom
UPDATE 14th April 2020: This note has been re-released with updated ‘validity’, and ‘Support Packages & Patches’ information. We added the validity for CRYSTAL REPORTS FOR VS 2010 and SP027 respectively.
Crystal Reports Designer allows an attacker with basic authorization to inject code that can be executed by the application. The attacker could hence control the behavior of the application.
Some well-known impacts of the vulnerability are:
- Unauthorized execution of arbitrary commands.
- Sensitive information disclosure.
- Denial of Service or system crashing.
- Inserting system commands, writing, deleting, or reading files.
Solution
This issue is fixed in the patches listed in the "Support Packages & Patches" section below. The application has been updated with safer functions and implementations. The "Support Packages & Patches" section will be populated with the relevant patch levels once they are released.
Reason and prerequisites
An attacker needs to upload a file to the platform and have it opened by a user to perform the attack.
CVSS
Score 8.2 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Full note on SAP: SAP Support Launchpad note 2861301
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
