Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Businessobjects

First CVE: Jan 10, 2001Active for: 26 yearsTotal CVEs: 13
41.5
VTI Score
High

BusinessObjects maintains a portfolio of enterprise reporting and business intelligence products—including Crystal Reports, Crystal Enterprise, WebIntelligence, and InfoView—that serve analytics and data-delivery functions across many organizations. The vendor's disclosures cluster around input-handling and memory-safety weakness classes, including cross-site scripting, buffer overflows, and race conditions in shared-resource access, and frequently acquire public exploit code. Current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 28% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Businessobjects over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2001
25 years ago
Most Recent CVE
Apr 18, 2008
6,671 days ago

Products(10 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-0204HIGH
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2
Aug 6, 20047.568NOYES
CVE-2006-6133HIGH
Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Ob
Nov 28, 20067.657NOYES
CVE-2008-0379HIGH
Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to cause a denial of service (cras
Jan 22, 20089.336NOYES
CVE-2003-1249HIGH
WebIntelligence 2.7.1 uses guessable user session cookies, which allows remote attackers to hijack sessions.
Dec 31, 20037.524NONO
CVE-2001-1464HIGH
Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows r
Jan 10, 20017.520NONO
CVE-2006-4099HIGH
Business Objects Crystal Enterprise 9 and 10 generates predictable session identifiers, which allows remote attackers to hijack sessions of other users via WCSID cookie values.
Nov 29, 20067.519NONO
CVE-2004-2742MEDIUM
Cross-site scripting (XSS) vulnerability in the report viewer in Crystal Enterprise 8.5, 9, and 10 allows remote attackers to inject arbitrary web script or HTML via script in the
Dec 31, 20044.318NONO
CVE-2008-1894MEDIUM
Cross-site scripting (XSS) vulnerability in desktoplaunch/InfoView/logon/logon.object in BusinessObjects InfoView XI R2 SP1, SP2, and SP3 Java version before FixPack 3.5 allows rem
Apr 18, 20084.316NONO
CVE-2005-4813MEDIUM
Unspecified vulnerability in Report Application Server (Crystalras.exe) before 11.0.0.1370, as used in Business Objects Crystal Reports XI, Crystal Reports Server XI, and BusinessO
Dec 31, 20055.015NONO
CVE-2005-4274MEDIUM
Unspecified vulnerability in Business Objects WebIntelligence 6.5x allows remote attackers to cause a denial of service (user account lock out) via unknown attack vectors related t
Dec 15, 20055.015NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
46%
46%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown13 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown13 (100.0%)
User Interaction
None0 (0.0%)
Unknown13 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown13 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
23.1% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Businessobjects.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Businessobjects — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Businessobjects's Products

View all 1 CNAs →

Top CWEs