The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including credentials which can be misused by the attacker.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=517899114 | vendor advisory |
https://launchpad.support.sap.com/#/notes/2687663 | permissions required vendor advisory |
http://packetstormsecurity.com/files/153471/SAP-Crystal-Reports-Information-Disclosure.html |