CVE-2021-40500: XEE
SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML validations at endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation can enable the attacker to retrieve arbitrary files from the server.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-40500.
What is the severity of CVE-2021-40500?
The severity of CVE-2021-40500 is high.
Which versions of SAP BusinessObjects Business Intelligence Platform are affected by this vulnerability?
Versions 4.20 and 4.30 of SAP BusinessObjects Business Intelligence Platform are affected by this vulnerability.
What can an unauthenticated attacker do with CVE-2021-40500?
An unauthenticated attacker can exploit missing XML validations at endpoints to read sensitive data.
Are there any references available for CVE-2021-40500?
Yes, you can find references for CVE-2021-40500 at the following links: [Reference 1](https://launchpad.support.sap.com/#/notes/3074693) and [Reference 2](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983).