CVE-2004-0534: XSS
Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows remote attackers to inject arbitrary web script or HTML via document names when uploading a document.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0534?
CVE-2004-0534 is considered a medium severity vulnerability due to its ability to allow cross-site scripting attacks.
How do I fix CVE-2004-0534?
To fix CVE-2004-0534, upgrade to a version of SAP BusinessObjects InfoView and Web Intelligence that is not affected, typically version 5.1.9 or later.
What products are affected by CVE-2004-0534?
CVE-2004-0534 affects SAP BusinessObjects InfoView versions 5.1.4 to 5.1.8 and SAP BusinessObjects Web Intelligence versions 2.7.0 to 2.7.4.
Can CVE-2004-0534 be exploited remotely?
Yes, CVE-2004-0534 can be exploited remotely by injecting malicious scripts via document names during the upload process.
What is the impact of CVE-2004-0534?
The impact of CVE-2004-0534 includes potential unauthorized access to user sessions and stealing sensitive information through cross-site scripting.