businessobjects kayıtları
businessobjects üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
52Planlayın | CVE-2004-0204Kavram kanıtı | Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used bea · weblogic server | Yüksek7,5 | — | %72,4 | 6 Ağu 2004 |
46Planlayın | CVE-2006-6133Kavram kanıtı | Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, andmicrosoft · visual studio .net · CWE-119 | Yüksek7,6 | — | %52,0 | 27 Kas 2006 |
40Planlayın | CVE-2008-0379Kavram kanıtı | Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attabusinessobjects · crystal reports xi · CWE-120 | Kritik9,3 | — | %8,6 | 22 Oca 2008 |
31İzleyin | CVE-2001-1464İstismar yok | Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in tbusinessobjects · crystal reports | Yüksek7,5 | — | %4,0 | 10 Oca 2001 |
31İzleyin | CVE-2003-1249İstismar yok | WebIntelligence 2.7.1 uses guessable user session cookies, which allows remote attackers to hijack sessions.businessobjects · webintelligence | Yüksek7,5 | — | %2,6 | 31 Ara 2003 |
31İzleyin | CVE-2006-4099İstismar yok | Business Objects Crystal Enterprise 9 and 10 generates predictable session identifiers, which allows remote attackers to hijack sessions of businessobjects · crystal enterprise | Yüksek7,5 | — | %1,7 | 29 Kas 2006 |
21İzleyin | CVE-2005-4813İstismar yok | Unspecified vulnerability in Report Application Server (Crystalras.exe) before 11.0.0.1370, as used in Business Objects Crystal Reports XI, businessobjects · crystal enterprise xi | Orta5,0 | — | %1,8 | 31 Ara 2005 |
20İzleyin | CVE-2004-1981İstismar yok | The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting reportbusinessobjects · crystal enterprise | Orta5,0 | — | %1,6 | 2 May 2004 |
20İzleyin | CVE-2005-4274İstismar yok | Unspecified vulnerability in Business Objects WebIntelligence 6.5x allows remote attackers to cause a denial of service (user account lock obusinessobjects · webintelligence | Orta5,0 | — | %1,3 | 15 Ara 2005 |
18İzleyin | CVE-2008-1894İstismar yok | Cross-site scripting (XSS) vulnerability in desktoplaunch/InfoView/logon/logon.object in BusinessObjects InfoView XI R2 SP1, SP2, and SP3 Jabusinessobjects · infoview · CWE-79 | Orta4,3 | — | %2,0 | 18 Nis 2008 |
17İzleyin | CVE-2004-2742İstismar yok | Cross-site scripting (XSS) vulnerability in the report viewer in Crystal Enterprise 8.5, 9, and 10 allows remote attackers to inject arbitrabusinessobjects · crystal enterprise · CWE-79 | Orta4,3 | — | %1,2 | 31 Ara 2004 |
17İzleyin | CVE-2004-0534İstismar yok | Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows rembusinessobjects · infoview | Orta4,3 | — | %1,2 | 17 Eyl 2004 |
8İzleyin | CVE-2004-0533İstismar yok | Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users tobusinessobjects · infoview | Düşük2,1 | — | %0,7 | 31 Ara 2004 |
- CVE-2004-020452Planlayın
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used
YüksekCVSS 7,5Kavram kanıtıEPSS %72bea · weblogic server6 Ağu 2004
- CVE-2006-613346Planlayın
Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and
YüksekCVSS 7,6Kavram kanıtıEPSS %52microsoft · visual studio .net27 Kas 2006
- CVE-2008-037940Planlayın
Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote atta
KritikCVSS 9,3Kavram kanıtıEPSS %9businessobjects · crystal reports xi22 Oca 2008
- CVE-2001-146431İzleyin
Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in t
YüksekCVSS 7,5İstismar yokEPSS %4businessobjects · crystal reports10 Oca 2001
- CVE-2003-124931İzleyin
WebIntelligence 2.7.1 uses guessable user session cookies, which allows remote attackers to hijack sessions.
YüksekCVSS 7,5İstismar yokEPSS %3businessobjects · webintelligence31 Ara 2003
- CVE-2006-409931İzleyin
Business Objects Crystal Enterprise 9 and 10 generates predictable session identifiers, which allows remote attackers to hijack sessions of
YüksekCVSS 7,5İstismar yokEPSS %2businessobjects · crystal enterprise29 Kas 2006
- CVE-2005-481321İzleyin
Unspecified vulnerability in Report Application Server (Crystalras.exe) before 11.0.0.1370, as used in Business Objects Crystal Reports XI,
OrtaCVSS 5,0İstismar yokEPSS %2businessobjects · crystal enterprise xi31 Ara 2005
- CVE-2004-198120İzleyin
The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting report
OrtaCVSS 5,0İstismar yokEPSS %2businessobjects · crystal enterprise2 May 2004
- CVE-2005-427420İzleyin
Unspecified vulnerability in Business Objects WebIntelligence 6.5x allows remote attackers to cause a denial of service (user account lock o
OrtaCVSS 5,0İstismar yokEPSS %1businessobjects · webintelligence15 Ara 2005
- CVE-2008-189418İzleyin
Cross-site scripting (XSS) vulnerability in desktoplaunch/InfoView/logon/logon.object in BusinessObjects InfoView XI R2 SP1, SP2, and SP3 Ja
OrtaCVSS 4,3İstismar yokEPSS %2businessobjects · infoview18 Nis 2008
- CVE-2004-274217İzleyin
Cross-site scripting (XSS) vulnerability in the report viewer in Crystal Enterprise 8.5, 9, and 10 allows remote attackers to inject arbitra
OrtaCVSS 4,3İstismar yokEPSS %1businessobjects · crystal enterprise31 Ara 2004
- CVE-2004-053417İzleyin
Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows rem
OrtaCVSS 4,3İstismar yokEPSS %1businessobjects · infoview17 Eyl 2004
- CVE-2004-05338İzleyin
Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to
DüşükCVSS 2,1İstismar yokEPSS %1businessobjects · infoview31 Ara 2004