CVE-2020-0618

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:sql_server:2012:sp4:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:2014:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:2016:sp2:*:*:*:*:x64:*

History

01 Jan 2022, 19:59

Type Values Removed Values Added
CWE CWE-20 CWE-502
References (MISC) http://packetstormsecurity.com/files/159216/Microsoft-SQL-Server-Reporting-Services-2016-Remote-Code-Execution.html - (MISC) http://packetstormsecurity.com/files/159216/Microsoft-SQL-Server-Reporting-Services-2016-Remote-Code-Execution.html - Exploit, Third Party Advisory, VDB Entry
References (MISC) http://packetstormsecurity.com/files/156707/SQL-Server-Reporting-Services-SSRS-ViewState-Deserialization.html - (MISC) http://packetstormsecurity.com/files/156707/SQL-Server-Reporting-Services-SSRS-ViewState-Deserialization.html - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2020-02-11 22:15

Updated : 2023-12-10 13:13


NVD link : CVE-2020-0618

Mitre link : CVE-2020-0618

CVE.ORG link : CVE-2020-0618


JSON object : View

Products Affected

microsoft

  • sql_server
CWE
CWE-502

Deserialization of Untrusted Data