First published: Wed Jan 10 2001(Updated: )
Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Crystal Reports |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1464 has a high severity, as it exposes sensitive credentials in cleartext.
To fix CVE-2001-1464, ensure that you upgrade to a patched version of SAP Crystal Reports that addresses this vulnerability.
CVE-2001-1464 can facilitate credential theft, allowing remote attackers to capture usernames and passwords from the URL.
Yes, CVE-2001-1464 is easily exploitable as it relies on embedded credentials within HTML pages.
CVE-2001-1464 affects various versions of SAP Crystal Reports that improperly handle credentials for password protected databases.