cbcvebase.
CVE-2019-0285
published 2019-04-10

CVE-2019-0285: The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including credentials…

PriorityP259critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
6.61%
93.1th percentile
The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including credentials which can be misused by the attacker.

Affected

2 ranges
VendorProductVersion rangeFixed in
sapcrystal_reports
sap_sesap_crystal_reports_for_visual_studio< 20102010

Detection & IOCsextracted from sources · hover to see the quote

cookie__CRYSTALSTATE
  • Intercept HTTP requests for Crystal Reports 'Export' functionality and inspect the '__CRYSTALSTATE' parameter for a base64-encoded value containing database credentials, internal paths, and debug information.
  • Monitor HTTP requests to SAP Crystal Reports .NET SDK WebForm Viewer endpoints for exfiltration of the '__CRYSTALSTATE' parameter, which leaks sensitive DB credentials in base64-encoded form.
  • ·Vulnerability is confirmed in SAP Crystal Reports for Visual Studio version 2010; the fix is also applied in version 2010 (patched release). Verify the exact patch level before assuming exposure.
  • ·Exploitation requires the ability to intercept an 'Export' report HTTP request (e.g., via a man-in-the-middle or authenticated session), limiting the attack surface to network-accessible or authenticated scenarios.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.