First published: Thu Sep 04 2014(Updated: )
Double free vulnerability in SAP Crystal Reports allows remote attackers to execute arbitrary code via crafted connection string record in an RPT file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Crystal Reports Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5506 has a critical severity level due to its potential to allow remote code execution.
The vulnerability can be mitigated by applying the latest patches and updates provided by SAP for Crystal Reports.
CVE-2014-5506 can be exploited by attackers using crafted RPT files containing malicious connection strings.
CVE-2014-5506 affects multiple versions of SAP Crystal Reports prior to the fixes released in SAP's security updates.
Exploitation of CVE-2014-5506 may allow attackers to execute arbitrary code on the victim's system, leading to a complete system compromise.