CVE-2020-6208 Information

Description

SAP Business Objects Business Intelligence Platform (Crystal Reports) versions- 4.1 4.2 allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the behaviour of the application leading to Remote Code Execution. Although the mode of attack is only Local multiple applications can be impacted as a result of the vulnerability.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Reference

https://launchpad.support.sap.com//notes/2861301 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305 https://www.zerodayinitiative.com/advisories/ZDI-20-291/

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.2

Share on: