First published: Tue Oct 12 2021(Updated: )
SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML validations at endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation can enable the attacker to retrieve arbitrary files from the server.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Businessobjects Business Intelligence Platform | =4.20 | |
Sap Businessobjects Business Intelligence Platform | =4.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-40500.
The severity of CVE-2021-40500 is high.
Versions 4.20 and 4.30 of SAP BusinessObjects Business Intelligence Platform are affected by this vulnerability.
An unauthenticated attacker can exploit missing XML validations at endpoints to read sensitive data.
Yes, you can find references for CVE-2021-40500 at the following links: [Reference 1](https://launchpad.support.sap.com/#/notes/3074693) and [Reference 2](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983).