Vulnerability Description
SAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML entities during crystal report generation due to missing XML validation, An attacker with basic privileges can inject some arbitrary XML entities leading to internal file disclosure, internal directories disclosure, Server-Side Request Forgery (SSRF) and denial-of-service (DoS).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Businessobjects Business Intelligence Platform | 4.1 |
References
- https://launchpad.support.sap.com/#/notes/2989075Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564757079Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2989075Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564757079Vendor Advisory
FAQ
What is CVE-2020-26831?
CVE-2020-26831 is a vulnerability with a CVSS score of 9.6 (CRITICAL). SAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML entities during crystal report generation due to missing XML validation, An atta...
How severe is CVE-2020-26831?
CVE-2020-26831 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-26831?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Businessobjects Business Intelligence Platform.