First published: Fri Sep 17 2004(Updated: )
Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows remote attackers to inject arbitrary web script or HTML via document names when uploading a document.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects | =5.1.8 | |
SAP BusinessObjects Web Intelligence | =2.7 | |
SAP BusinessObjects Web Intelligence | =2.7.3 | |
SAP BusinessObjects | =5.1.6 | |
SAP BusinessObjects Web Intelligence | =2.7.2 | |
SAP BusinessObjects | =5.1.5 | |
SAP BusinessObjects | =5.1.4 | |
SAP BusinessObjects Web Intelligence | =2.7.1 | |
SAP BusinessObjects Web Intelligence | =2.7.4 | |
SAP BusinessObjects | =5.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0534 is considered a medium severity vulnerability due to its ability to allow cross-site scripting attacks.
To fix CVE-2004-0534, upgrade to a version of SAP BusinessObjects InfoView and Web Intelligence that is not affected, typically version 5.1.9 or later.
CVE-2004-0534 affects SAP BusinessObjects InfoView versions 5.1.4 to 5.1.8 and SAP BusinessObjects Web Intelligence versions 2.7.0 to 2.7.4.
Yes, CVE-2004-0534 can be exploited remotely by injecting malicious scripts via document names during the upload process.
The impact of CVE-2004-0534 includes potential unauthorized access to user sessions and stealing sensitive information through cross-site scripting.