CVE-2020-26831: SSRF
SAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML entities during crystal report generation due to missing XML validation, An attacker with basic privileges can inject some arbitrary XML entities leading to internal file disclosure, internal directories disclosure, Server-Side Request Forgery (SSRF) and denial-of-service (DoS).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26831?
The severity of CVE-2020-26831 is critical with a CVSS score of 9.6.
Which versions of SAP BusinessObjects BI Platform are affected by CVE-2020-26831?
CVE-2020-26831 affects versions 4.1, 4.2, and 4.3 of SAP BusinessObjects BI Platform.
What is the impact of CVE-2020-26831?
CVE-2020-26831 allows an attacker with basic privileges to inject arbitrary XML entities and disclose internal files.
How can an attacker exploit CVE-2020-26831?
To exploit CVE-2020-26831, an attacker can upload a malicious XML file containing arbitrary entities.
Are there any recommended mitigations for CVE-2020-26831?
Yes, SAP has released security notes and patches to address CVE-2020-26831. It is recommended to apply the latest patches provided by SAP to mitigate the vulnerability.