The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including credentials which can be misused by the attacker.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/153471/SAP-Crystal-Reports-Information-Disclosure.html | |
https://launchpad.support.sap.com/#/notes/2687663 | Permissions Required Vendor Advisory |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=517899114 | Vendor Advisory |
http://packetstormsecurity.com/files/153471/SAP-Crystal-Reports-Information-Disclosure.html | |
https://launchpad.support.sap.com/#/notes/2687663 | Permissions Required Vendor Advisory |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=517899114 | Vendor Advisory |
Configurations
History
21 Nov 2024, 04:16
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/153471/SAP-Crystal-Reports-Information-Disclosure.html - | |
References | () https://launchpad.support.sap.com/#/notes/2687663 - Permissions Required, Vendor Advisory | |
References | () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=517899114 - Vendor Advisory |
Information
Published : 2019-04-10 21:29
Updated : 2024-11-21 04:16
NVD link : CVE-2019-0285
Mitre link : CVE-2019-0285
CVE.ORG link : CVE-2019-0285
JSON object : View
Products Affected
sap
- crystal_reports
CWE
CWE-312
Cleartext Storage of Sensitive Information