Business Objects WebIntelligence Access Control Bypass File Deletion Vulnerability
BID:11208
Info
Business Objects WebIntelligence Access Control Bypass File Deletion Vulnerability
| Bugtraq ID: | 11208 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-0533 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 17 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | Discovery of this issue is credited to Corsaire Limited. |
| Vulnerable: |
Business Objects WebIntelligence 2.7.4 Business Objects WebIntelligence 2.7.3 Business Objects WebIntelligence 2.7.2 Business Objects WebIntelligence 2.7.1 Business Objects WebIntelligence 2.7 Business Objects InfoView 5.1.8 Business Objects InfoView 5.1.7 Business Objects InfoView 5.1.6 Business Objects InfoView 5.1.5 Business Objects InfoView 5.1.4 |
| Not Vulnerable: | |
Discussion
Business Objects WebIntelligence Access Control Bypass File Deletion Vulnerability
It is reported that WebIntelligence is susceptible to an access control bypass vulnerability allowing for the deletion of files from the application.
This vulnerability is reported to exist as access controls are only enforced on the client. The server fails to enforce access control restriction and allows delete requests to succeed when they are not authorized.
Only authenticated users are able to exploit this vulnerability.
It is reported that WebIntelligence is susceptible to an access control bypass vulnerability allowing for the deletion of files from the application.
This vulnerability is reported to exist as access controls are only enforced on the client. The server fails to enforce access control restriction and allows delete requests to succeed when they are not authorized.
Only authenticated users are able to exploit this vulnerability.
Exploit / POC
Business Objects WebIntelligence Access Control Bypass File Deletion Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Business Objects WebIntelligence Access Control Bypass File Deletion Vulnerability
Solution:
The vendor has released patches dealing with this issue. Users are recommended to contact the vendor for patch and update availability.
Solution:
The vendor has released patches dealing with this issue. Users are recommended to contact the vendor for patch and update availability.
References
Business Objects WebIntelligence Access Control Bypass File Deletion Vulnerability
References:
References:
- Vendor Homepage (Business Objects)
- WebIntelligence Product Page (Business Objects)