CVE-2020-6208
Last modified
CVE-2020-6208 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the behaviour of the application, leading to Remote Code Execution. Although the mode of attack is only Local, multiple applications can be impacted as a result of the vulnerability.. EPSS estimates a 1.14% chance of exploitation in the next 30 days.
Description
SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the behaviour of the application, leading to Remote Code Execution. Although the mode of attack is only Local, multiple applications can be impacted as a result of the vulnerability.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Crystal Reports | 4.1 |
| Sap | Crystal Reports | 4.2 |
References
- https://launchpad.support.sap.com/#/notes/2861301Permissions Required
- https://www.zerodayinitiative.com/advisories/ZDI-20-291/Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2861301Permissions Required
- https://www.zerodayinitiative.com/advisories/ZDI-20-291/Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-6208?
How severe is CVE-2020-6208?
How do I fix CVE-2020-6208?
Are you affected by CVE-2020-6208?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
