Vulnerability Description
SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Reports for VS version 2010, allows an attacker with basic authorization to perform deserialization attack in the application, leading to service interruptions and denial of service and unauthorized execution of arbitrary commands, leading to Deserialization of Untrusted Data.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Businessobjects Business Intelligence Platform | 4.1 |
| Sap | Crystal Reports For Visual Studio | 2010 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2863731Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=544214202Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2863731Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=544214202Vendor Advisory
FAQ
What is CVE-2020-6219?
CVE-2020-6219 is a vulnerability with a CVSS score of 8.8 (HIGH). SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Reports for VS version 2010, allows an attacker with basic authorization to perform ...
How severe is CVE-2020-6219?
CVE-2020-6219 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6219?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Businessobjects Business Intelligence Platform, Sap Crystal Reports For Visual Studio.