CVE-2020-6208 Information
Feb 14, 2021
cve
Description
SAP Business Objects Business Intelligence Platform (Crystal Reports) versions- 4.1 4.2 allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the behaviour of the application leading to Remote Code Execution. Although the mode of attack is only Local multiple applications can be impacted as a result of the vulnerability.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Reference
https://launchpad.support.sap.com//notes/2861301 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305 https://www.zerodayinitiative.com/advisories/ZDI-20-291/
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.2
Share on: