CVE Database
/

CVE-2020-6219

Back to search

CVE-2020-6219

Published: Apr 14, 2020

Modified: Aug 4, 2024

PUBLISHED

CVSS v3.0

9.1

CRITICAL

Description

SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Reports for VS version 2010, allows an attacker with basic authorization to perform deserialization attack in the application, leading to service interruptions and denial of service and unauthorized execution of arbitrary commands, leading to Deserialization of Untrusted Data.

VendorProductVersions

SAP SE

SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer)

affected
< 4.1
affected
< 4.2

SAP SE

Crystal Reports for VS

affected
< 2010

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Changed

Confidentiality

Low

Integrity

Low

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now