VulnerabilityModified
CVE-2004-0533
Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client.
LOW 2.1EPSS 0.69%
Does this matter?
Lower severity and a low EPSS score (0.69%). Track it; it rarely justifies an emergency change on its own.
Description
Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Affected
- businessobjects/infoview · businessobjects/webintelligence
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0056.htmlVendor Advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026549.htmlVendor Advisory
- http://secunia.com/advisories/12587/Vendor Advisory
- http://www.securityfocus.com/bid/11208
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17422
- http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0056.htmlVendor Advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026549.htmlVendor Advisory
- http://secunia.com/advisories/12587/Vendor Advisory
- http://www.securityfocus.com/bid/11208
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17422
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.