漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
SQL Server Reporting Services Security Feature Bypass Vulnerability
Vulnerability Description
<p>A security feature bypass vulnerability exists in SQL Server Reporting Services (SSRS) when the server improperly validates attachments uploaded to reports. An attacker who successfully exploited this vulnerability could upload file types that were disallowed by an administrator.</p> <p>To exploit the vulnerability, an authenticated attacker would need to send a specially crafted request to an affected SSRS server.</p> <p>The update addresses the vulnerability by modifying how SSRS validates attachment uploads.</p>
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
N/A
Vulnerability Title
Microsoft Windows SQL Server Reporting Services (SSRS) 输入验证错误漏洞
Vulnerability Description
Microsoft Windows是美国微软(Microsoft)公司的一套个人设备使用的操作系统。 Microsoft Windows SQL Server Reporting Services (SSRS)中存在安全漏洞,该漏洞允许攻击者向受影响的SSRS服务器发送经过特殊设计的请求,从而上传管理员不允许的文件类型。以下产品及版本受到影响: SQL Server 2017 Reporting Services版本, SQL Server 2019 Reporting Services版本。
CVSS Information
N/A
Vulnerability Type
N/A