First published: Fri Dec 31 2004(Updated: )
Cross-site scripting (XSS) vulnerability in the report viewer in Crystal Enterprise 8.5, 9, and 10 allows remote attackers to inject arbitrary web script or HTML via script in the URL to a report (RPT) file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Crystal Enterprise | =8.5 | |
SAP BusinessObjects Crystal Enterprise | =10 | |
SAP BusinessObjects Crystal Enterprise | =10 | |
SAP BusinessObjects Crystal Enterprise | =8.5 | |
SAP BusinessObjects Crystal Enterprise | =10 | |
SAP BusinessObjects Crystal Enterprise | =10 | |
SAP BusinessObjects Crystal Enterprise | =10 | |
SAP BusinessObjects Crystal Enterprise | =9 | |
SAP BusinessObjects Crystal Enterprise | =8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2742 has a medium severity rating as it allows for cross-site scripting attacks which can compromise user data.
To fix CVE-2004-2742, upgrade your Crystal Enterprise to a patched version that addresses the XSS vulnerability.
CVE-2004-2742 affects users of SAP BusinessObjects Crystal Enterprise versions 8.5, 9, and 10 across multiple operating systems.
CVE-2004-2742 can be exploited to perform cross-site scripting attacks, potentially allowing the attacker to steal session cookies or redirect users.
Yes, CVE-2004-2742 is a remote vulnerability that can be exploited by attackers over the internet.