PT-2018-2616 · Sap · Crystal Reports+1
Published
2018-09-11
·
Updated
2020-08-24
·
CVE-2018-2458
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Business One versions 9.2 and 9.3
Description
The issue is related to errors in access restriction in the Crystal Report component of SAP Business One, which can allow an attacker to access restricted information under certain conditions. Exploitation of this issue may enable a remote attacker to gain unauthorized access to protected information.
Recommendations
For versions 9.2 and 9.3, consider restricting access to the Crystal Report component until a fix is available.
As a temporary workaround, review and tighten access controls and permissions related to the Crystal Report connection type to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Crystal Reports
Sap Business One