Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential remote code execution in SAP CrystalReports, SAP security note 1999142

SAP Note 1999142

SAP security note 1999142, "Potential remote code execution in SAP CrystalReports". Below are the symptom and SAP recommended solution.

Description

Symptom

UPDATE 20th June 2018: This note has been re-released, with updated ‘Support Packages & Patches’ and CVSS information.

UPDATE 11th June 2018: This note has been re-released, updating the CVSS from v2 to v3.

An attacker can exploit SAP CrystalReports to enable them to inject code into the working memory that is subsequently executed by the application.

Solution

The issue has been fixed in the following SAP BusinessObjects Enterprise and SAP Crystal Reports for Microsoft Visual Studio releases. Please apply the below listed packages:

  • SAP BusinessObjects Enterprise 4.0 SP09 Patch5
  • SAP BusinessObjects Enterprise 4.1 SP04 Patch1
  • SAP Crystal Reports, version for Microsoft Visual Studio SP23

Reason and prerequisites

A buffer overflow vulnerability exists in SAP CrystalReports. This enables an attacker to inject code into the working memory that is subsequently executed by the application. It can also be used to cause a general fault in the product, causing the product to terminate.

CVSS

Score 6.6 Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H

Full note on SAP: SAP Support Launchpad note 1999142

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More