PT-2021-22907 · Sap · Sap Businessobjects Business Intelligence Platform

Published

2021-10-12

·

Updated

2021-10-18

·

CVE-2021-40500

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP BusinessObjects Business Intelligence Platform (Crystal Reports) versions 420, 430
Description The issue allows an unauthenticated attacker to exploit missing XML validations at endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation can enable the attacker to retrieve arbitrary files from the server.
Recommendations For versions 420 and 430, consider restricting access to the exposed endpoints to minimize the risk of exploitation until a fix is available. As a temporary workaround, disabling the endpoints or implementing additional validation for XML inputs may help mitigate the risk.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-40500

Affected Products

Sap Businessobjects Business Intelligence Platform