CVE-2018-2427: SAP Businessobjects Business Intelligence
High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.
SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application.
Affected products
- SAP Businessobjects Business Intelligence: version 4.10 only; version 4.20 only
- SAP Crystal Reports: affected versions not specified
Published 2018-07-10. Last modified 2026-06-17.