SAP security note 2863731, "[CVE-2020-6219] Deserialization of Untrusted Data in SAP Business Objects Business Intelligence Platform (CR .Net SDK WebForm Viewer)", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Crystal Reports .Net SDK WebForm Viewer allows an attacker with basic authorization to perform a deserialization attack in the application, potentially leading to code execution.
- Availability: Total loss of service availability, enabling full denial of access to resources in the impacted component.
- Integrity: Unauthorized execution of arbitrary commands.
Solution
The data transmission between the server and client has been encrypted to ensure secure information transmission, preventing tampering during deserialization. This issue is addressed in the patches listed below.
CVSS
Score 9.1 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
Affected components
- Business intelligence solutions > Reporting, analysis, and dashboards > SAP Crystal Reports Viewer (BI-RA-CRV)
- ENTERPRISE 410, 420, 430; CRYSTAL REPORTS FOR VS 2010
Full note on SAP: SAP Support Launchpad note 2863731
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
