First published: Tue Mar 10 2020(Updated: )
SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the behaviour of the application, leading to Remote Code Execution. Although the mode of attack is only Local, multiple applications can be impacted as a result of the vulnerability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Crystal Reports | ||
Sap Crystal Reports | =4.1 | |
Sap Crystal Reports | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6208 is a vulnerability in SAP Crystal Reports that allows remote attackers to execute arbitrary code.
CVE-2020-6208 relies on a use-after-free vulnerability in the parsing of RPT files in SAP Crystal Reports.
CVE-2020-6208 has a severity rating of 8.2, which is considered high.
SAP Crystal Reports versions 4.1 and 4.2 are affected by CVE-2020-6208.
To mitigate the risk of CVE-2020-6208, it is recommended to update SAP Crystal Reports to a patched version provided by SAP.