PT-2018-2616 · Sap · Crystal Reports+1
Publicado
2018-09-11
·
Atualizado
2020-08-24
·
CVE-2018-2458
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Business One versions 9.2 and 9.3
Description
The issue is related to errors in access restriction in the Crystal Report component of SAP Business One, which can allow an attacker to access restricted information under certain conditions. Exploitation of this issue may enable a remote attacker to gain unauthorized access to protected information.
Recommendations
For versions 9.2 and 9.3, consider restricting access to the Crystal Report component until a fix is available.
As a temporary workaround, review and tighten access controls and permissions related to the Crystal Report connection type to minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Crystal Reports
Sap Business One