SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/104715 | Third Party Advisory VDB Entry |
https://launchpad.support.sap.com/#/notes/2620738 | Permissions Required |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/104715 | Third Party Advisory VDB Entry |
https://launchpad.support.sap.com/#/notes/2620738 | Permissions Required |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:03
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/104715 - Third Party Advisory, VDB Entry | |
References | () https://launchpad.support.sap.com/#/notes/2620738 - Permissions Required | |
References | () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000 - Patch, Vendor Advisory |
Information
Published : 2018-07-10 18:29
Updated : 2024-11-21 04:03
NVD link : CVE-2018-2427
Mitre link : CVE-2018-2427
CVE.ORG link : CVE-2018-2427
JSON object : View
Products Affected
sap
- crystal_reports
- businessobjects_business_intelligence
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')