CVE-2018-2427: Code Injection
SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-2427.
What is the severity of CVE-2018-2427?
The severity of CVE-2018-2427 is high with a severity value of 8.8.
What is affected by CVE-2018-2427?
SAP BusinessObjects Business Intelligence Suite versions 4.10 and 4.20, as well as SAP Crystal Reports (version for Visual Studio .NET, Version 2010), are affected by this vulnerability.
How can an attacker exploit CVE-2018-2427?
An attacker can exploit CVE-2018-2427 by injecting code that can be executed by the application, allowing them to control its behavior.
Are there any references for CVE-2018-2427?
Yes, there are references available for CVE-2018-2427. You can find them at the following links: securityfocus.com/bid/104715, launchpad.support.sap.com/#/notes/2620738, and wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000.