businessobjects records
13 published records for vendor businessobjects.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
52Plan | CVE-2004-0204Proof of concept | Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used bea · weblogic server | High7.5 | — | 72.4% | Aug 6, 2004 |
46Plan | CVE-2006-6133Proof of concept | Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, andmicrosoft · visual studio .net · CWE-119 | High7.6 | — | 52.0% | Nov 27, 2006 |
40Plan | CVE-2008-0379Proof of concept | Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attabusinessobjects · crystal reports xi · CWE-120 | Critical9.3 | — | 8.6% | Jan 22, 2008 |
31Monitor | CVE-2001-1464No exploit | Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in tbusinessobjects · crystal reports | High7.5 | — | 4.0% | Jan 10, 2001 |
31Monitor | CVE-2003-1249No exploit | WebIntelligence 2.7.1 uses guessable user session cookies, which allows remote attackers to hijack sessions.businessobjects · webintelligence | High7.5 | — | 2.6% | Dec 31, 2003 |
31Monitor | CVE-2006-4099No exploit | Business Objects Crystal Enterprise 9 and 10 generates predictable session identifiers, which allows remote attackers to hijack sessions of businessobjects · crystal enterprise | High7.5 | — | 1.7% | Nov 29, 2006 |
21Monitor | CVE-2005-4813No exploit | Unspecified vulnerability in Report Application Server (Crystalras.exe) before 11.0.0.1370, as used in Business Objects Crystal Reports XI, businessobjects · crystal enterprise xi | Medium5.0 | — | 1.8% | Dec 31, 2005 |
20Monitor | CVE-2004-1981No exploit | The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting reportbusinessobjects · crystal enterprise | Medium5.0 | — | 1.6% | May 2, 2004 |
20Monitor | CVE-2005-4274No exploit | Unspecified vulnerability in Business Objects WebIntelligence 6.5x allows remote attackers to cause a denial of service (user account lock obusinessobjects · webintelligence | Medium5.0 | — | 1.3% | Dec 15, 2005 |
18Monitor | CVE-2008-1894No exploit | Cross-site scripting (XSS) vulnerability in desktoplaunch/InfoView/logon/logon.object in BusinessObjects InfoView XI R2 SP1, SP2, and SP3 Jabusinessobjects · infoview · CWE-79 | Medium4.3 | — | 2.0% | Apr 18, 2008 |
17Monitor | CVE-2004-2742No exploit | Cross-site scripting (XSS) vulnerability in the report viewer in Crystal Enterprise 8.5, 9, and 10 allows remote attackers to inject arbitrabusinessobjects · crystal enterprise · CWE-79 | Medium4.3 | — | 1.2% | Dec 31, 2004 |
17Monitor | CVE-2004-0534No exploit | Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows rembusinessobjects · infoview | Medium4.3 | — | 1.2% | Sep 17, 2004 |
8Monitor | CVE-2004-0533No exploit | Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users tobusinessobjects · infoview | Low2.1 | — | 0.7% | Dec 31, 2004 |
- CVE-2004-020452Plan
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used
HighCVSS 7.5Proof of conceptEPSS 72%bea · weblogic serverAug 6, 2004
- CVE-2006-613346Plan
Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and
HighCVSS 7.6Proof of conceptEPSS 52%microsoft · visual studio .netNov 27, 2006
- CVE-2008-037940Plan
Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote atta
CriticalCVSS 9.3Proof of conceptEPSS 9%businessobjects · crystal reports xiJan 22, 2008
- CVE-2001-146431Monitor
Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in t
HighCVSS 7.5No exploitEPSS 4%businessobjects · crystal reportsJan 10, 2001
- CVE-2003-124931Monitor
WebIntelligence 2.7.1 uses guessable user session cookies, which allows remote attackers to hijack sessions.
HighCVSS 7.5No exploitEPSS 3%businessobjects · webintelligenceDec 31, 2003
- CVE-2006-409931Monitor
Business Objects Crystal Enterprise 9 and 10 generates predictable session identifiers, which allows remote attackers to hijack sessions of
HighCVSS 7.5No exploitEPSS 2%businessobjects · crystal enterpriseNov 29, 2006
- CVE-2005-481321Monitor
Unspecified vulnerability in Report Application Server (Crystalras.exe) before 11.0.0.1370, as used in Business Objects Crystal Reports XI,
MediumCVSS 5.0No exploitEPSS 2%businessobjects · crystal enterprise xiDec 31, 2005
- CVE-2004-198120Monitor
The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting report
MediumCVSS 5.0No exploitEPSS 2%businessobjects · crystal enterpriseMay 2, 2004
- CVE-2005-427420Monitor
Unspecified vulnerability in Business Objects WebIntelligence 6.5x allows remote attackers to cause a denial of service (user account lock o
MediumCVSS 5.0No exploitEPSS 1%businessobjects · webintelligenceDec 15, 2005
- CVE-2008-189418Monitor
Cross-site scripting (XSS) vulnerability in desktoplaunch/InfoView/logon/logon.object in BusinessObjects InfoView XI R2 SP1, SP2, and SP3 Ja
MediumCVSS 4.3No exploitEPSS 2%businessobjects · infoviewApr 18, 2008
- CVE-2004-274217Monitor
Cross-site scripting (XSS) vulnerability in the report viewer in Crystal Enterprise 8.5, 9, and 10 allows remote attackers to inject arbitra
MediumCVSS 4.3No exploitEPSS 1%businessobjects · crystal enterpriseDec 31, 2004
- CVE-2004-053417Monitor
Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows rem
MediumCVSS 4.3No exploitEPSS 1%businessobjects · infoviewSep 17, 2004
- CVE-2004-05338Monitor
Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to
LowCVSS 2.1No exploitEPSS 1%businessobjects · infoviewDec 31, 2004