microsoft sql-server-reporting-services CVE-2020-1044 is a vulnerability in Microsoft Sql Server Reporting Services
Published on September 11, 2020

<p>A security feature bypass vulnerability exists in SQL Server Reporting Services (SSRS) when the server improperly validates attachments uploaded to reports. An attacker who successfully exploited this vulnerability could upload file types that were disallowed by an administrator.</p> <p>To exploit the vulnerability, an authenticated attacker would need to send a specially crafted request to an affected SSRS server.</p> <p>The update addresses the vulnerability by modifying how SSRS validates attachment uploads.</p>

NVD


Products Associated with CVE-2020-1044

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-1044 are published in Microsoft Sql Server Reporting Services:

 

Affected Versions

Microsoft SQL Server 2017 Reporting Services: Microsoft SQL Server 2019 Reporting Services:

Exploit Probability

EPSS
4.45%
Percentile
88.65%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.