5
CVSSv2

CVE-2021-40500

Published: 12/10/2021 Updated: 18/10/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated malicious user to exploit missing XML validations at endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation can enable the malicious user to retrieve arbitrary files from the server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap businessobjects business intelligence platform 4.20

sap businessobjects business intelligence platform 4.30