Sap Crystal Reports vulnerabilities

4 known vulnerabilities affecting sap/crystal_reports.

Total CVEs
4
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH1

Vulnerabilities

Page 1 of 1
CVE-2020-6208HIGHCVSS 8.2v4.1v4.22020-03-10
CVE-2020-6208 [HIGH] CWE-416 CVE-2020-6208: SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the behaviour of the application, leading to Remote Code Execution. Although the mode of attack is only Local, multiple app
nvd
CVE-2019-0285CRITICALCVSS 9.8PoCv20102019-04-10
CVE-2019-0285 [CRITICAL] CWE-312 CVE-2019-0285: The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) disclos The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including credentials which can be misused by the attacker.
nvd
CVE-2010-2590CRITICALCVSS 9.3PoCv20082010-12-22
CVE-2010-2590 [CRITICAL] CWE-119 CVE-2010-2590: Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintCon Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Reports 2008 SP3 Fix Pack 3.2 allows remote attackers to execute arbitrary code via a long ServerResourceVersion property value.
nvd
CVE-2010-3032CRITICALCVSS 10.0v20082010-08-17
CVE-2010-3032 [CRITICAL] CWE-189 CVE-2010-3032: Integer overflow in the OBGIOPServerWorker::extractHeader function in the ebus-3-3-2-6.dll module in Integer overflow in the OBGIOPServerWorker::extractHeader function in the ebus-3-3-2-6.dll module in SAP Crystal Reports 2008 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GIOP packet with a crafted size, which triggers a heap-based buffer overflow.
nvd