HTTP: SAP Crystal Reports Server ActiveX Insecure Method Vulnerability

This signature detects attempts to exploit known multiple insecure-method vulnerabilities in SAP Crystal Reports Server ActiveX Control. A remote attacker can leverage this by enticing a target user to open a malicious Web page. A successful attack allows an attacker to execute arbitrary code in the security context of the logged in user. An unsuccessful attack can cause an abnormal termination of the affected browser.

Extended Description

The SAP Crystal Reports Server ActiveX control is prone to multiple insecure-method vulnerabilities. Successful exploits will compromise affected computers or cause denial-of-service conditions; other attacks are possible. SAP Crystal Reports Server 2008 is vulnerable.

Affected Products

Sap crystal_reports_server_2008

Short Name
HTTP:STC:ACTIVEX:SAP-CRSTL-RPT
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ActiveX Crystal Insecure Method Reports SAP Server Vulnerability bid:45977
Release Date
03/11/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Sap

Found a potential security threat?