CVE-2004-0204
Summary
| CVE | CVE-2004-0204 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-08-06 04:00:00 UTC |
| Updated | 2018-10-12 21:34:00 UTC |
| Description | Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bea | Weblogic Server | 8.1 | All | All | All |
| Application | Bea | Weblogic Server | 8.1 | All | express | All |
| Application | Bea | Weblogic Server | 8.1 | All | win32 | All |
| Application | Bea | Weblogic Server | 8.1 | sp1 | All | All |
| Application | Bea | Weblogic Server | 8.1 | sp1 | express | All |
| Application | Bea | Weblogic Server | 8.1 | sp1 | win32 | All |
| Application | Bea | Weblogic Server | 8.1 | sp2 | All | All |
| Application | Bea | Weblogic Server | 8.1 | sp2 | express | All |
| Application | Bea | Weblogic Server | 8.1 | sp2 | win32 | All |
| Application | Bea | Weblogic Server | 8.1 | All | All | All |
| Application | Bea | Weblogic Server | 8.1 | All | express | All |
| Application | Bea | Weblogic Server | 8.1 | All | win32 | All |
| Application | Bea | Weblogic Server | 8.1 | sp1 | All | All |
| Application | Bea | Weblogic Server | 8.1 | sp1 | express | All |
| Application | Bea | Weblogic Server | 8.1 | sp1 | win32 | All |
| Application | Bea | Weblogic Server | 8.1 | sp2 | All | All |
| Application | Bea | Weblogic Server | 8.1 | sp2 | express | All |
| Application | Bea | Weblogic Server | 8.1 | sp2 | win32 | All |
| Application | Borland Software | J Builder | All | All | All | All |
| Application | Borland Software | J Builder | All | All | All | All |
| Application | Businessobjects | Crystal Enterprise | 10 | All | All | All |
| Application | Businessobjects | Crystal Enterprise | 9 | All | All | All |
| Application | Businessobjects | Crystal Enterprise | 10 | All | All | All |
| Application | Businessobjects | Crystal Enterprise | 9 | All | All | All |
| Application | Businessobjects | Crystal Enterprise Java Sdk | 8.5 | All | All | All |
| Application | Businessobjects | Crystal Enterprise Java Sdk | 8.5 | All | All | All |
| Application | Businessobjects | Crystal Enterprise Ras | 8.5 | All | unix | All |
| Application | Businessobjects | Crystal Enterprise Ras | 8.5 | All | unix | All |
| Application | Businessobjects | Crystal Reports | 10 | All | All | All |
| Application | Businessobjects | Crystal Reports | 9 | All | All | All |
| Application | Businessobjects | Crystal Reports | 10 | All | All | All |
| Application | Businessobjects | Crystal Reports | 9 | All | All | All |
| Application | Microsoft | Business Solutions Crm | 1.2 | All | All | All |
| Application | Microsoft | Business Solutions Crm | 1.2 | All | All | All |
| Application | Microsoft | Outlook | 2003 | All | business_contact_manager | All |
| Application | Microsoft | Outlook | 2003 | All | business_contact_manager | All |
| Application | Microsoft | Visual Studio .net | 2003 | gold | All | All |
| Application | Microsoft | Visual Studio .net | 2003 | gold | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| 'Crystal Reports Vulnerabilities' - MARC | BUGTRAQ | marc.info | |
| Business Objects Crystal Reports Web Form Viewer Directory Traversal Vulnerability | BID | www.securityfocus.com | Exploit, Patch, Vendor Advisory |
| Critical Updates: Business Objects Security Bulletin - Business Objects | CONFIRM | support.businessobjects.com | |
| Secunia - Advisories - Crystal Reports and Crystal Enterprise Directory Traversal Vulnerability | SECUNIA | secunia.com | |
| 6748 | OSVDB | www.osvdb.org | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Microsoft Security Bulletin MS04-017 - Moderate | Microsoft Docs | MS | docs.microsoft.com | |
| 'Vulnerability: Arbitrary File Access & DoS in Crystal Reports' - MARC | BUGTRAQ | marc.info | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.