CVE-2020-26831 is a critical XML external entity (XXE) vulnerability affecting SAP BusinessObjects BI Platform (Crystal Report) versions 4.1, 4.2, and 4.3. The flaw stems from insufficient validation of uploaded XML entities during crystal report generation, allowing attackers with basic privileges to inject arbitrary XML. This can lead to severe impacts including internal file and directory disclosure, Server-Side Request Forgery (SSRF), and denial-of-service (DoS). With a CVSS score of 9.6 (Critical) and a FAUCET Risk Score of 92/100, the vulnerability is easily exploitable over the network with low privileges and complexity, resulting in high confidentiality and availability impacts. While there is no known active exploitation or public exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion with 11 mentions and media coverage, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.1CPE matchmatch criteria | cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.1:-:*:*:*:*:*:* | ||
4.2CPE matchmatch criteria | cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.2:-:*:*:*:*:*:* | ||
4.3CPE matchmatch criteria | cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.