CVE-2001-1464

Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords.
References
Link Resource
http://www.kb.cert.org/vuls/id/403307 Exploit Third Party Advisory US Government Resource
https://exchange.xforce.ibmcloud.com/vulnerabilities/7928
Configurations

Configuration 1 (hide)

cpe:2.3:a:businessobjects:crystal_reports:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2001-01-10 05:00

Updated : 2023-12-10 10:17


NVD link : CVE-2001-1464

Mitre link : CVE-2001-1464

CVE.ORG link : CVE-2001-1464


JSON object : View

Products Affected

businessobjects

  • crystal_reports