PT-2020-11885 · Eclipse+1 · Birt+2

Published

2020-08-14

·

Updated

2020-08-21

·

CVE-2020-10055

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Desigo CC versions 3.x through 4.x Desigo CC Compact versions 3.x through 4.x
Description A remote code execution issue has been identified in the affected applications due to a vulnerable 3rd party component, BIRT, used in the Advanced Reporting Engine. If this engine is enabled, a remote unauthenticated attacker could execute arbitrary commands on the server with SYSTEM privileges.
Recommendations For Desigo CC versions 3.x through 4.x, disable the Advanced Reporting Engine until a patch is available. For Desigo CC Compact versions 3.x through 4.x, disable the Advanced Reporting Engine until a patch is available.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10055

Affected Products

Birt
Desigo Cc
Desigo Cc Compact