Skip links
Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential code injection vulnerability in Crystal Reports Java components, SAP security note 2557167

Description

Crystal Reports Java components could allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

Available fix and Supported packages

  • ENTERPRISE | 410 | 410
  • ENTERPRISE | 420 | 420
  • ENTERPRISE | 430 | 430
  • SBOP BI PLATFORM SERVERS 4.1 | SP011 | 000000
  • SBOP BI PLATFORM SERVERS 4.2 | SP006 | 000000

Affected component

    BI-RA-CRE
    Crystal Reports for Enterprise

CVSS

Score: 0

PoC

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/2557167

TAGS

#Crystal-Reports-for-Enterprise
#CR4E
#CRE
#BusinessObjects

More to explorer

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.