CVE-2009-3346: Critical severity SAP Crystal Reports Server vulnerability
Unspecified vulnerability in SAP Crystal Reports Server 2008 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3346?
CVE-2009-3346 is rated as a high severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2009-3346?
To mitigate CVE-2009-3346, it is recommended to update SAP Crystal Reports Server 2008 to a patched version provided by SAP.
What are the potential consequences of CVE-2009-3346?
Exploitation of CVE-2009-3346 may allow remote attackers to execute arbitrary code on the affected system.
Who is affected by CVE-2009-3346?
CVE-2009-3346 affects users of SAP Crystal Reports Server 2008.
What vectors may be used to exploit CVE-2009-3346?
The specific vectors for exploiting CVE-2009-3346 have not been detailed, making it challenging to assess the exact methods of attack.