CVE-2004-0533: Low severity BusinessObjects InfoView vulnerability
Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0533?
CVE-2004-0533 is considered to have a high severity level due to the potential for remote authenticated users to delete arbitrary files on the server.
How do I fix CVE-2004-0533?
To fix CVE-2004-0533, it is recommended to apply the latest security patches or updates provided by SAP BusinessObjects for the affected versions.
Which versions are affected by CVE-2004-0533?
CVE-2004-0533 affects Business Objects WebIntelligence versions 2.7.0 through 2.7.4 and InfoView versions 5.1.4 through 5.1.8.
Can unauthorized users exploit CVE-2004-0533?
No, CVE-2004-0533 requires that an attacker be an authenticated user to exploit the vulnerability.
What type of access control issue does CVE-2004-0533 relate to?
CVE-2004-0533 relates to a lack of effective server-side access control, allowing authenticated users to perform unauthorized file deletion.