Записи businessobjects
13 опубликованных записей вендора businessobjects.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
52В плане | CVE-2004-0204Proof of concept | Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used bea · weblogic server | Высокая7,5 | — | 72,4 % | 6 авг. 2004 г. |
46В плане | CVE-2006-6133Proof of concept | Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, andmicrosoft · visual studio .net · CWE-119 | Высокая7,6 | — | 52,0 % | 27 нояб. 2006 г. |
40В плане | CVE-2008-0379Proof of concept | Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attabusinessobjects · crystal reports xi · CWE-120 | Критическая9,3 | — | 8,6 % | 22 янв. 2008 г. |
31Наблюдать | CVE-2001-1464Эксплойта нет | Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in tbusinessobjects · crystal reports | Высокая7,5 | — | 4,0 % | 10 янв. 2001 г. |
31Наблюдать | CVE-2003-1249Эксплойта нет | WebIntelligence 2.7.1 uses guessable user session cookies, which allows remote attackers to hijack sessions.businessobjects · webintelligence | Высокая7,5 | — | 2,6 % | 31 дек. 2003 г. |
31Наблюдать | CVE-2006-4099Эксплойта нет | Business Objects Crystal Enterprise 9 and 10 generates predictable session identifiers, which allows remote attackers to hijack sessions of businessobjects · crystal enterprise | Высокая7,5 | — | 1,7 % | 29 нояб. 2006 г. |
21Наблюдать | CVE-2005-4813Эксплойта нет | Unspecified vulnerability in Report Application Server (Crystalras.exe) before 11.0.0.1370, as used in Business Objects Crystal Reports XI, businessobjects · crystal enterprise xi | Средняя5,0 | — | 1,8 % | 31 дек. 2005 г. |
20Наблюдать | CVE-2004-1981Эксплойта нет | The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting reportbusinessobjects · crystal enterprise | Средняя5,0 | — | 1,6 % | 2 мая 2004 г. |
20Наблюдать | CVE-2005-4274Эксплойта нет | Unspecified vulnerability in Business Objects WebIntelligence 6.5x allows remote attackers to cause a denial of service (user account lock obusinessobjects · webintelligence | Средняя5,0 | — | 1,3 % | 15 дек. 2005 г. |
18Наблюдать | CVE-2008-1894Эксплойта нет | Cross-site scripting (XSS) vulnerability in desktoplaunch/InfoView/logon/logon.object in BusinessObjects InfoView XI R2 SP1, SP2, and SP3 Jabusinessobjects · infoview · CWE-79 | Средняя4,3 | — | 2,0 % | 18 апр. 2008 г. |
17Наблюдать | CVE-2004-2742Эксплойта нет | Cross-site scripting (XSS) vulnerability in the report viewer in Crystal Enterprise 8.5, 9, and 10 allows remote attackers to inject arbitrabusinessobjects · crystal enterprise · CWE-79 | Средняя4,3 | — | 1,2 % | 31 дек. 2004 г. |
17Наблюдать | CVE-2004-0534Эксплойта нет | Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows rembusinessobjects · infoview | Средняя4,3 | — | 1,2 % | 17 сент. 2004 г. |
8Наблюдать | CVE-2004-0533Эксплойта нет | Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users tobusinessobjects · infoview | Низкая2,1 | — | 0,7 % | 31 дек. 2004 г. |
- CVE-2004-020452В плане
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used
ВысокаяCVSS 7,5Proof of conceptEPSS 72 %bea · weblogic server6 авг. 2004 г.
- CVE-2006-613346В плане
Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and
ВысокаяCVSS 7,6Proof of conceptEPSS 52 %microsoft · visual studio .net27 нояб. 2006 г.
- CVE-2008-037940В плане
Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote atta
КритическаяCVSS 9,3Proof of conceptEPSS 9 %businessobjects · crystal reports xi22 янв. 2008 г.
- CVE-2001-146431Наблюдать
Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in t
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %businessobjects · crystal reports10 янв. 2001 г.
- CVE-2003-124931Наблюдать
WebIntelligence 2.7.1 uses guessable user session cookies, which allows remote attackers to hijack sessions.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %businessobjects · webintelligence31 дек. 2003 г.
- CVE-2006-409931Наблюдать
Business Objects Crystal Enterprise 9 and 10 generates predictable session identifiers, which allows remote attackers to hijack sessions of
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %businessobjects · crystal enterprise29 нояб. 2006 г.
- CVE-2005-481321Наблюдать
Unspecified vulnerability in Report Application Server (Crystalras.exe) before 11.0.0.1370, as used in Business Objects Crystal Reports XI,
СредняяCVSS 5,0Эксплойта нетEPSS 2 %businessobjects · crystal enterprise xi31 дек. 2005 г.
- CVE-2004-198120Наблюдать
The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting report
СредняяCVSS 5,0Эксплойта нетEPSS 2 %businessobjects · crystal enterprise2 мая 2004 г.
- CVE-2005-427420Наблюдать
Unspecified vulnerability in Business Objects WebIntelligence 6.5x allows remote attackers to cause a denial of service (user account lock o
СредняяCVSS 5,0Эксплойта нетEPSS 1 %businessobjects · webintelligence15 дек. 2005 г.
- CVE-2008-189418Наблюдать
Cross-site scripting (XSS) vulnerability in desktoplaunch/InfoView/logon/logon.object in BusinessObjects InfoView XI R2 SP1, SP2, and SP3 Ja
СредняяCVSS 4,3Эксплойта нетEPSS 2 %businessobjects · infoview18 апр. 2008 г.
- CVE-2004-274217Наблюдать
Cross-site scripting (XSS) vulnerability in the report viewer in Crystal Enterprise 8.5, 9, and 10 allows remote attackers to inject arbitra
СредняяCVSS 4,3Эксплойта нетEPSS 1 %businessobjects · crystal enterprise31 дек. 2004 г.
- CVE-2004-053417Наблюдать
Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows rem
СредняяCVSS 4,3Эксплойта нетEPSS 1 %businessobjects · infoview17 сент. 2004 г.
- CVE-2004-05338Наблюдать
Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to
НизкаяCVSS 2,1Эксплойта нетEPSS 1 %businessobjects · infoview31 дек. 2004 г.