7.5
CVE-2004-0204
- EPSS 72.99%
- Veröffentlicht 06.08.2004 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:05:09
- Erkennungen
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bea ≫ Weblogic Server Version 8.1
Bea ≫ Weblogic Server Version 8.1 Edition express
Bea ≫ Weblogic Server Version 8.1 Edition win32
Bea ≫ Weblogic Server Version 8.1 Update sp1
Bea ≫ Weblogic Server Version 8.1 Update sp1 Edition express
Bea ≫ Weblogic Server Version 8.1 Update sp1 Edition win32
Bea ≫ Weblogic Server Version 8.1 Update sp2
Bea ≫ Weblogic Server Version 8.1 Update sp2 Edition express
Bea ≫ Weblogic Server Version 8.1 Update sp2 Edition win32
Businessobjects ≫ Crystal Enterprise Version 9
Businessobjects ≫ Crystal Enterprise Version 10
Businessobjects ≫ Crystal Enterprise Java Sdk Version 8.5
Businessobjects ≫ Crystal Enterprise Ras Version 8.5 Edition unix
Businessobjects ≫ Crystal Reports Version 9
Businessobjects ≫ Crystal Reports Version 10
Microsoft ≫ Business Solutions Crm Version 1.2
Microsoft ≫ Visual Studio .Net Version 2003 Update gold
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 72.99% | 0.994 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://marc.info/?l=bugtraq&m=108360413811017&w=2
http://marc.info/?l=bugtraq&m=108671836127360&w=2
http://secunia.com/advisories/11800
http://support.businessobjects.com/fix/hot/critical/bulletins/security_bulletin_june04.asp
http://www.osvdb.org/6748
http://www.securityfocus.com/bid/10260
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-017
https://exchange.xforce.ibmcloud.com/vulnerabilities/16044
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1157