First published: Fri Dec 31 2004(Updated: )
Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects | =5.1.8 | |
SAP BusinessObjects Web Intelligence | =2.7 | |
SAP BusinessObjects Web Intelligence | =2.7.3 | |
SAP BusinessObjects | =5.1.6 | |
SAP BusinessObjects Web Intelligence | =2.7.2 | |
SAP BusinessObjects | =5.1.5 | |
SAP BusinessObjects | =5.1.4 | |
SAP BusinessObjects Web Intelligence | =2.7.1 | |
SAP BusinessObjects Web Intelligence | =2.7.4 | |
SAP BusinessObjects | =5.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0533 is considered to have a high severity level due to the potential for remote authenticated users to delete arbitrary files on the server.
To fix CVE-2004-0533, it is recommended to apply the latest security patches or updates provided by SAP BusinessObjects for the affected versions.
CVE-2004-0533 affects Business Objects WebIntelligence versions 2.7.0 through 2.7.4 and InfoView versions 5.1.4 through 5.1.8.
No, CVE-2004-0533 requires that an attacker be an authenticated user to exploit the vulnerability.
CVE-2004-0533 relates to a lack of effective server-side access control, allowing authenticated users to perform unauthorized file deletion.