First published: Thu Sep 24 2009(Updated: )
Unspecified vulnerability in SAP Crystal Reports Server 2008 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Crystal Reports Server XI | =2008 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3346 is rated as a high severity vulnerability due to its potential for arbitrary code execution.
To mitigate CVE-2009-3346, it is recommended to update SAP Crystal Reports Server 2008 to a patched version provided by SAP.
Exploitation of CVE-2009-3346 may allow remote attackers to execute arbitrary code on the affected system.
CVE-2009-3346 affects users of SAP Crystal Reports Server 2008.
The specific vectors for exploiting CVE-2009-3346 have not been detailed, making it challenging to assess the exact methods of attack.