CVE-2019-0285: SAP Crystal Reports
Critical severity, CVSS 9.8. EPSS: 6.6% chance of exploitation in the next 30 days.
The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including credentials which can be misused by the attacker.
Affected products
- SAP Crystal Reports: version 2010 only
Published 2019-04-10. Last modified 2026-06-17.