PT-2019-2584 · Sap · Sap Crystal Reports For Visual Studio
Published
2019-04-10
·
Updated
2020-08-24
·
CVE-2019-0285
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP Crystal Reports for Visual Studio versions prior to 2010
Description
The issue is related to the disclosure of sensitive database information, including credentials, due to a lack of protection for service data. This can be exploited by an attacker to reveal protected information.
Recommendations
For versions prior to 2010, update to version 2010 to resolve the issue. As a temporary workaround, consider restricting access to the .NET SDK WebForm Viewer component to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Crystal Reports For Visual Studio