CVE-2020-1044
published 2020-09-11CVE-2020-1044: A security feature bypass vulnerability exists in SQL Server Reporting Services (SSRS) when the server improperly validates attachments uploaded to reports. An…
PriorityP341medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
1.91%
77.4th percentile
A security feature bypass vulnerability exists in SQL Server Reporting Services (SSRS) when the server improperly validates attachments uploaded to reports. An attacker who successfully exploited this vulnerability could upload file types that were disallowed by an administrator.
To exploit the vulnerability, an authenticated attacker would need to send a specially crafted request to an affected SSRS server.
The update addresses the vulnerability by modifying how SSRS validates attachment uploads.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | sql_server_2017_reporting_services | >= 14.0.0 < publication | publication |
| microsoft | sql_server_2019_reporting_services | >= 15.0.0 < publication | publication |
| microsoft | sql_server_reporting_services | — | — |
| microsoft | sql_server_reporting_services | — | — |
| msrc | sql_server_2017_reporting_services | — | — |
| msrc | sql_server_2019_reporting_services | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_msrc4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
SQL Server Reporting Services Security Feature Bypass Vulnerability
vendor_msrc·2020-09-08·CVSS 4.3
CVE-2020-1044 [MEDIUM] SQL Server Reporting Services Security Feature Bypass Vulnerability
SQL Server Reporting Services Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists in SQL Server Reporting Services (SSRS) when the server improperly validates attachments uploaded to reports. An attacker who successfully exploited this vulnerability could upload file types that were disallowed by an administrator.
To exploit the vulnerability, an authenticated attacker would need to send a specially crafted request to an affected SSRS server.
The update addresses the vulnerability by modifying how SSRS validates attachment uploads.
SQL Server: SQL Server
Microsoft: Microsoft
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation
GHSA
GHSA-j5c4-63f4-32wp: A security feature bypass vulnerability exists in SQL Server Reporting Services (SSRS) when the server improperly validates attachments uploaded to re
ghsa_unreviewed·2022-05-24
CVE-2020-1044 [MEDIUM] CWE-20 GHSA-j5c4-63f4-32wp: A security feature bypass vulnerability exists in SQL Server Reporting Services (SSRS) when the server improperly validates attachments uploaded to re
A security feature bypass vulnerability exists in SQL Server Reporting Services (SSRS) when the server improperly validates attachments uploaded to reports, aka 'SQL Server Reporting Services Security Feature Bypass Vulnerability'.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-09-11
Published