CVE-2020-6208
SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the behaviour of the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.14%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the behaviour of the application, leading to Remote Code Execution. Although the mode of attack is only Local, multiple applications can be impacted as a result of the vulnerability.
- CVSS 3.1
- 8.2 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
- EPSS
- 1.14% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- sap/crystal reports
- Source
- cna@sap.com
References
- https://launchpad.support.sap.com/#/notes/2861301Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-291/Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2861301Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-291/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.