Skip to content
Noroxi

businessobjects records

13 published records for vendor businessobjects.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

13 records
  • Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used

    HighCVSS 7.5Proof of conceptEPSS 72%

    bea · weblogic serverAug 6, 2004

  • Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and

    HighCVSS 7.6Proof of conceptEPSS 52%

    microsoft · visual studio .netNov 27, 2006

  • Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote atta

    CriticalCVSS 9.3Proof of conceptEPSS 9%

    businessobjects · crystal reports xiJan 22, 2008

  • CVE-2001-1464
    31Monitor

    Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in t

    HighCVSS 7.5No exploitEPSS 4%

    businessobjects · crystal reportsJan 10, 2001

  • CVE-2003-1249
    31Monitor

    WebIntelligence 2.7.1 uses guessable user session cookies, which allows remote attackers to hijack sessions.

    HighCVSS 7.5No exploitEPSS 3%

    businessobjects · webintelligenceDec 31, 2003

  • CVE-2006-4099
    31Monitor

    Business Objects Crystal Enterprise 9 and 10 generates predictable session identifiers, which allows remote attackers to hijack sessions of

    HighCVSS 7.5No exploitEPSS 2%

    businessobjects · crystal enterpriseNov 29, 2006

  • CVE-2005-4813
    21Monitor

    Unspecified vulnerability in Report Application Server (Crystalras.exe) before 11.0.0.1370, as used in Business Objects Crystal Reports XI,

    MediumCVSS 5.0No exploitEPSS 2%

    businessobjects · crystal enterprise xiDec 31, 2005

  • CVE-2004-1981
    20Monitor

    The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting report

    MediumCVSS 5.0No exploitEPSS 2%

    businessobjects · crystal enterpriseMay 2, 2004

  • CVE-2005-4274
    20Monitor

    Unspecified vulnerability in Business Objects WebIntelligence 6.5x allows remote attackers to cause a denial of service (user account lock o

    MediumCVSS 5.0No exploitEPSS 1%

    businessobjects · webintelligenceDec 15, 2005

  • CVE-2008-1894
    18Monitor

    Cross-site scripting (XSS) vulnerability in desktoplaunch/InfoView/logon/logon.object in BusinessObjects InfoView XI R2 SP1, SP2, and SP3 Ja

    MediumCVSS 4.3No exploitEPSS 2%

    businessobjects · infoviewApr 18, 2008

  • CVE-2004-2742
    17Monitor

    Cross-site scripting (XSS) vulnerability in the report viewer in Crystal Enterprise 8.5, 9, and 10 allows remote attackers to inject arbitra

    MediumCVSS 4.3No exploitEPSS 1%

    businessobjects · crystal enterpriseDec 31, 2004

  • CVE-2004-0534
    17Monitor

    Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows rem

    MediumCVSS 4.3No exploitEPSS 1%

    businessobjects · infoviewSep 17, 2004

  • Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to

    LowCVSS 2.1No exploitEPSS 1%

    businessobjects · infoviewDec 31, 2004