peter bassill · operator
$ cve CVE-2019-0285 JSON

CVE-2019-0285 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 6.6% (pctl 94)

Patch early

A public exploit exists.

Description

The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including credentials which can be misused by the attacker.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.61% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-312
On CISA KEVno
Public exploityes
Published2019-04-10
Last modified2026-06-17

Affected (1)

VendorProduct
sapcrystal reports

Public exploits

SourceTitleDate
exploit-dbSAP Crystal Reports - Information Disclosure2019-07-01

References

→ the Explorer  ·  watch your stack  ·  NVD