<p>A security feature bypass vulnerability exists in SQL Server Reporting Services (SSRS) when the server improperly validates attachments uploaded to reports. An attacker who successfully exploited this vulnerability could upload file types that were disallowed by an administrator.</p>
<p>To exploit the vulnerability, an authenticated attacker would need to send a specially crafted request to an affected SSRS server.</p>
<p>The update addresses the vulnerability by modifying how SSRS validates attachment uploads.</p>
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: microsoft
Published: 2020-09-11T17:08:54
Updated: 2024-08-04T06:25:00.771Z
Reserved: 2019-11-04T00:00:00
Link: CVE-2020-1044
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-09-11T17:15:18.260
Modified: 2024-11-21T05:09:37.700
Link: CVE-2020-1044
Redhat
No data.