SAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML entities during crystal report generation due to missing XML validation, An attacker with basic privileges can inject some arbitrary XML entities leading to internal file disclosure, internal directories disclosure, Server-Side Request Forgery (SSRF) and denial-of-service (DoS).
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:HSap Businessobjects Business Intelligence Platform
APPSap4.14.24.3
Related vulnerabilities
Stored XSS w SAP BusinessObjects BI Platform CMC — CVSS 10.0
SAP BusinessObjects BI — zdalne wykonanie kodu przez uwierzytelnionego użytkownika
SAP BusinessObjects BI Platform – brak uwierzytelnienia w komponencie Xvfb (Unix)
SAP BusinessObjects BI Platform — logowanie bez hasła do CMC (Missing Authentication)
SAP BusinessObjects BI Platform CMC ujawnia hasło w plaintext w odpowiedzi HTTP