Short Name |
HTTP:STC:ACTIVEX:SAP-CRSTL-RPT |
---|---|
Severity |
Major |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
SAP Crystal Reports Server ActiveX Insecure Method Vulnerability |
Release Date |
2011/03/11 |
Update Number |
1881 |
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit known multiple insecure-method vulnerabilities in SAP Crystal Reports Server ActiveX Control. A remote attacker can leverage this by enticing a target user to open a malicious Web page. A successful attack allows an attacker to execute arbitrary code in the security context of the logged in user. An unsuccessful attack can cause an abnormal termination of the affected browser.
The SAP Crystal Reports Server ActiveX control is prone to multiple insecure-method vulnerabilities. Successful exploits will compromise affected computers or cause denial-of-service conditions; other attacks are possible. SAP Crystal Reports Server 2008 is vulnerable.