Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2020-1044

Опубликовано: 08 сент. 2020
Источник: msrc
CVSS3: 4.3
EPSS Низкий

Описание

SQL Server Reporting Services Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in SQL Server Reporting Services (SSRS) when the server improperly validates attachments uploaded to reports. An attacker who successfully exploited this vulnerability could upload file types that were disallowed by an administrator.

To exploit the vulnerability, an authenticated attacker would need to send a specially crafted request to an affected SSRS server.

The update addresses the vulnerability by modifying how SSRS validates attachment uploads.

Обновления

ПродуктСтатьяОбновление
SQL Server 2017 Reporting Services
SQL Server 2019 Reporting Services

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 89%
0.04445
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
больше 5 лет назад

<p>A security feature bypass vulnerability exists in SQL Server Reporting Services (SSRS) when the server improperly validates attachments uploaded to reports. An attacker who successfully exploited this vulnerability could upload file types that were disallowed by an administrator.</p> <p>To exploit the vulnerability, an authenticated attacker would need to send a specially crafted request to an affected SSRS server.</p> <p>The update addresses the vulnerability by modifying how SSRS validates attachment uploads.</p>

CVSS3: 4.3
github
больше 3 лет назад

A security feature bypass vulnerability exists in SQL Server Reporting Services (SSRS) when the server improperly validates attachments uploaded to reports, aka 'SQL Server Reporting Services Security Feature Bypass Vulnerability'.

CVSS3: 4.3
fstec
больше 5 лет назад

Уязвимость серверной системы создания отчётов SQL Server Reporting Services, связанная с ошибками при обработке входных данных, позволяющая нарушителю загружать файлы с недопустимыми типами

EPSS

Процентиль: 89%
0.04445
Низкий

4.3 Medium

CVSS3