The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including credentials which can be misused by the attacker.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/153471/SAP-Crystal-Reports-Information-Disclosure.html | |
https://launchpad.support.sap.com/#/notes/2687663 | Permissions Required Vendor Advisory |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=517899114 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2019-04-10 21:29
Updated : 2020-08-24 17:37
NVD link : CVE-2019-0285
Mitre link : CVE-2019-0285
CVE.ORG link : CVE-2019-0285
JSON object : View
Products Affected
sap
- crystal_reports
CWE
CWE-312
Cleartext Storage of Sensitive Information