SAP Crystal Reports Remote Code Execution Vulnerability
Released on: 2014-09-03
Updated on: 2014-09-05
Affected Systems:
SAP Crystal Reports
Description:
--------------------------------------------------------------------------------
Bugtraq id: 69557
CVE (CAN) ID: CVE-2014-5506
SAP Crystal Reports is a business intelligence application used to design and generate Reports.
SAP Crystal Reports has a security vulnerability in processing RPT files. This vulnerability is due to the handling of connection string records. Attackers can exploit this vulnerability to execute arbitrary code in the context of the current process.
<* Source: Aniway.Anyway@gmail.com
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SAP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://service.sap.com/sap/support/notes/1999142
This article permanently updates the link address: