← Back

CVE-2004-0533

nvd nist
Published: Dec 31, 2004Modified: Apr 16, 2026

JSON object

Loading...
2.1
Vector
AV:L/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 3.9 / Impact: 2.9
Source: NVD

Description

Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client.

Affected (10)

2 products
Infoview
Webintelligence
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Businessobjects
Version 5.1.4
Version 5.1.5
Version 5.1.6
Version 5.1.7
Version 5.1.8
Businessobjects
Version 2.7.1
Version 2.7.2
Version 2.7.3
Version 2.7.4
Version 2.7

References (10)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.