cancel
Showing results for 
Search instead for 
Did you mean: 

CWE 377 Insecure Temporary File vulnerability in Crystal Reports Java Runtime 11.8.6.1371

07-14-2026 3:46 AM
Sammy-99_ Explorer
203 views 3 comments Go to solution
0 Likes
SAP Managed Tags
Subscribe

We have a Crystal Reports Java runtime bundle version 11.8.6.1371.Veracode has identified CWE 377 (Insecure Temporary File) vulnerabilities in the following Crystal Reports runtime components:

  • webreporting.jar
  • CrystalExporters.jar
  • CrystalReportingCommon.jar

Which SAP Crystal Reports Java runtime/service pack version contains the fix for CWE 377 . Is upgrading the complete Crystal runtime bundle required, or are individual JAR replacements supported or please advise if any other fix to resolve this. 

0 Likes

Accepted Solutions (1)

Accepted Solutions (1)

DonWilliams
Active Contributor

Crystal Reports 11.5 is end of Life now, no more patches available.

And the CR SDK's are no longer shipped with Crystal Reports.

You can upgrade to CR for Eclipse now:

https://www.eclipse.org/downloads/

It will require you to update your project and references.

 

 

 

Sammy-99_
Explorer
0 Likes
Thanks for the guidance. Just to confirm for our setup : Is CR for Eclipse usable for server side runtime (not just report design)? Is Java 8 on WebSphere (WAS 9 ) supported? Can old JRC APIs still be used, or is rewrite needed? Any official migration guide from JRC 11.x?
DonWilliams
Active Contributor
0 Likes
Sorry, wrong link to CR for Eclipse, all info is here: https://help.sap.com/docs/SUPPORT_CONTENT/crystalreports/3354088796.html?locale=en-US

Answers (0)