Directory Traversal Vulnerability in Crystal Reports and Crystal Enterprise

A directory traversal vulnerability exists in Crystal Reports and Crystal Enterprise from Business Objects, which could result in information disclosure and a Denial of Service (DoS).

Ken Pfeil

June 8, 2004

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported June 08, 2004, byMicrosoft

VERSIONS AFFECTED

DESCRIPTION
A directory traversal vulnerability exists in Crystal Reports and CrystalEnterprise from Business Objects,which could result in information disclosure and a Denial of Service (DoS). Apotential attacker who successfully exploits this vulnerability could retrieveand delete files through the Crystal Reports and Crystal Enterprise Web viewerson the vulnerable system. (Visual Studio .NET 2003 and Outlook 2003 withBusiness Contact Manager redistribute Crystal Reports; Business Solutions CRM1.2 redistributes Crystal Enterprise.) The number of files that thisvulnerability affects depends on the security context of the affected componentthat the Crystal Web viewer uses. Systems can be vulnerable only if they haveMicrosoft Internet Information Services (IIS) installed.

VENDOR RESPONSE
Microsoft has releasedbulletin MS04-017, "Vulnerability in Crystal Reports Web ViewerCould Allow Information Disclosure and Denial of Service" (842689), toaddress this vulnerability and recommends that affected users apply theappropriate patch listed in the bulletin.

CREDIT
Discovered by Business Objects.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like