Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

Potential code injection vulnerability in Crystal Reports Java components, SAP security note 2557167

Description

Crystal Reports Java components could allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

Available fix and Supported packages

  • ENTERPRISE | 410 | 410
  • ENTERPRISE | 420 | 420
  • ENTERPRISE | 430 | 430
  • SBOP BI PLATFORM SERVERS 4.1 | SP011 | 000000
  • SBOP BI PLATFORM SERVERS 4.2 | SP006 | 000000

Affected component

    BI-RA-CRE
    Crystal Reports for Enterprise

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/2557167

TAGS

#Crystal-Reports-for-Enterprise
#CR4E
#CRE
#BusinessObjects

More to explorer

SAP Cloud Connector Certificate Validation Issue

Date of Release: February 13, 2024 Advisory ID: CVE-2024-25642 Affected Software: SAP Cloud Connector Versions Affected: 2.15.0 to 2.16.1 Vulnerability Summary:A critical vulnerability,