First published: Tue Sep 11 2018(Updated: )
Under certain conditions, Crystal Report using SAP Business One, versions 9.2 and 9.3, connection type allows an attacker to access information which would otherwise be restricted.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Business One | =9.2 | |
Sap Business One | =9.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2458 is a vulnerability in Crystal Report using SAP Business One versions 9.2 and 9.3 that allows an attacker to access restricted information.
The severity of CVE-2018-2458 is high with a CVSS score of 7.5.
Crystal Report using SAP Business One versions 9.2 and 9.3 are affected.
An attacker can exploit CVE-2018-2458 by exploiting the vulnerable connection type in Crystal Report.
Yes, you can find more information about CVE-2018-2458 at the following references: [1] http://www.securityfocus.com/bid/105307 [2] https://launchpad.support.sap.com/#/notes/2670284 [3] https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499356993