CVE-2018-2427
Estado: ModificadaAlta (8.8)—
SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.71%
- Percentil entre todas las CVEs puntuadas: 77
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-94
Referencias
- http://www.securityfocus.com/bid/104715
- https://launchpad.support.sap.com/#/notes/2620738
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000
- http://www.securityfocus.com/bid/104715
- https://launchpad.support.sap.com/#/notes/2620738
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-2427",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cna@sap.com",
"affectedData": [
{
"vendor": "SAP",
"product": "SAP BusinessObjects Business Intelligence Suite",
"versions": [
{
"status": "affected",
"version": "= 4.10"
},
{
"status": "affected",
"version": "= 4.20"
}
]
},
{
"vendor": "SAP",
"product": "SAP Crystal Reports",
"versions": [
{
"status": "affected",
"version": "= version for Visual Studio .NET, Version 2010"
}
]
}
]
}
],
"published": "2018-07-10T18:29:00.767",
"references": [
{
"url": "http://www.securityfocus.com/bid/104715",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cna@sap.com"
},
{
"url": "https://launchpad.support.sap.com/#/notes/2620738",
"tags": [
"Permissions Required"
],
"source": "cna@sap.com"
},
{
"url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cna@sap.com"
},
{
"url": "http://www.securityfocus.com/bid/104715",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://launchpad.support.sap.com/#/notes/2620738",
"tags": [
"Permissions Required"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application."
},
{
"lang": "es",
"value": "SAP BusinessObjects Business Intelligence Suite, en versiones 4.10 y 4.20, y SAP Crystal Reports (versión para Visual Studio .NET, Version 2010) permite que un atacante inyecte código que puede ser ejecutado por la aplicación. Un atacante podría, por lo tanto, controlar el comportamiento de la aplicación."
}
],
"lastModified": "2026-06-17T01:55:40.967",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:businessobjects_business_intelligence:4.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E42DCEF8-02FD-478F-BE45-B4F5D916E6DE"
},
{
"criteria": "cpe:2.3:a:sap:businessobjects_business_intelligence:4.20:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D99D62B4-D2DD-4BDC-9660-D607D86259E3"
},
{
"criteria": "cpe:2.3:a:sap:crystal_reports:-:*:*:*:*:visual_studio_.net_2010:*:*",
"vulnerable": true,
"matchCriteriaId": "274A169F-42A5-4A5A-83A9-A7695A6F112F"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cna@sap.com"
}