First published: Tue Jul 10 2018(Updated: )
SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | =4.10 | |
SAP BusinessObjects Business Intelligence | =4.20 | |
Sap Crystal Reports |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2018-2427.
The severity of CVE-2018-2427 is high with a severity value of 8.8.
SAP BusinessObjects Business Intelligence Suite versions 4.10 and 4.20, as well as SAP Crystal Reports (version for Visual Studio .NET, Version 2010), are affected by this vulnerability.
An attacker can exploit CVE-2018-2427 by injecting code that can be executed by the application, allowing them to control its behavior.
Yes, there are references available for CVE-2018-2427. You can find them at the following links: securityfocus.com/bid/104715, launchpad.support.sap.com/#/notes/2620738, and wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000.