CVE-2019-0285 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 6.6% (pctl 94)
Patch early
A public exploit exists.
Description
The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including credentials which can be misused by the attacker.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.61% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-312 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-04-10 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| sap | crystal reports |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SAP Crystal Reports - Information Disclosure | 2019-07-01 |
References
- http://packetstormsecurity.com/files/153471/SAP-Crystal-Reports-Information-Disclosure.html
- https://launchpad.support.sap.com/#/notes/2687663
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=517899114
- http://packetstormsecurity.com/files/153471/SAP-Crystal-Reports-Information-Disclosure.html
- https://launchpad.support.sap.com/#/notes/2687663
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=517899114
→ the Explorer · watch your stack · NVD