CVE-2018-2406: Path Traversal
Published Apr 10, 2018
·Updated
Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0, 4.10, 4.20, 4.30, startup path.
Affected Software
4 affected components
SAP Crystal Reports Server=4.0
SAP Crystal Reports Server=4.10
SAP Crystal Reports Server=4.20
SAP Crystal Reports Server=4.30
Event History
Apr 10, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-2406?
CVE-2018-2406 has a medium severity rating due to its potential for exploitation in unquoted search paths.
2
How do I fix CVE-2018-2406?
To fix CVE-2018-2406, ensure that the directory paths used in the startup configuration are correctly quoted.
3
Which versions are affected by CVE-2018-2406?
CVE-2018-2406 affects SAP Crystal Reports Server versions 4.0, 4.10, 4.20, and 4.30.
4
What types of vulnerabilities does CVE-2018-2406 represent?
CVE-2018-2406 represents a directory/path traversal vulnerability due to unquoted search paths.
5
Can CVE-2018-2406 lead to data exposure?
Yes, CVE-2018-2406 can potentially allow an attacker to execute arbitrary code, leading to data exposure.