Directory Traversal Vulnerability in Crystal Reports and Crystal Enterprise
A directory traversal vulnerability exists in Crystal Reports and Crystal Enterprise from Business Objects, which could result in information disclosure and a Denial of Service (DoS).
June 8, 2004
Reported June 08, 2004, byMicrosoft
VERSIONS AFFECTED
DESCRIPTION
A directory traversal vulnerability exists in Crystal Reports and CrystalEnterprise from Business Objects,which could result in information disclosure and a Denial of Service (DoS). Apotential attacker who successfully exploits this vulnerability could retrieveand delete files through the Crystal Reports and Crystal Enterprise Web viewerson the vulnerable system. (Visual Studio .NET 2003 and Outlook 2003 withBusiness Contact Manager redistribute Crystal Reports; Business Solutions CRM1.2 redistributes Crystal Enterprise.) The number of files that thisvulnerability affects depends on the security context of the affected componentthat the Crystal Web viewer uses. Systems can be vulnerable only if they haveMicrosoft Internet Information Services (IIS) installed.
VENDOR RESPONSE
Microsoft has releasedbulletin MS04-017, "Vulnerability in Crystal Reports Web ViewerCould Allow Information Disclosure and Denial of Service" (842689), toaddress this vulnerability and recommends that affected users apply theappropriate patch listed in the bulletin.
CREDIT
Discovered by Business Objects.
About the Author
You May Also Like