CVE-2018-2406: SAP Crystal Reports Server

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0, 4.10, 4.20, 4.30, startup path.

Affected products

  • SAP Crystal Reports Server: version 4.0 only; version 4.10 only; version 4.20 only; version 4.30 only

Published 2018-04-10. Last modified 2026-06-17.