BusinessObjects maintains a portfolio of enterprise reporting and business intelligence products—including Crystal Reports, Crystal Enterprise, WebIntelligence, and InfoView—that serve analytics and data-delivery functions across many organizations. The vendor's disclosures cluster around input-handling and memory-safety weakness classes, including cross-site scripting, buffer overflows, and race conditions in shared-resource access, and frequently acquire public exploit code. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Businessobjects over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0204HIGH Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2 | Aug 6, 2004 | 7.5 | 68 | NO | YES |
CVE-2006-6133HIGH Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Ob | Nov 28, 2006 | 7.6 | 57 | NO | YES |
CVE-2008-0379HIGH Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to cause a denial of service (cras | Jan 22, 2008 | 9.3 | 36 | NO | YES |
CVE-2003-1249HIGH WebIntelligence 2.7.1 uses guessable user session cookies, which allows remote attackers to hijack sessions. | Dec 31, 2003 | 7.5 | 24 | NO | NO |
CVE-2001-1464HIGH Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows r | Jan 10, 2001 | 7.5 | 20 | NO | NO |
CVE-2006-4099HIGH Business Objects Crystal Enterprise 9 and 10 generates predictable session identifiers, which allows remote attackers to hijack sessions of other users via WCSID cookie values. | Nov 29, 2006 | 7.5 | 19 | NO | NO |
CVE-2004-2742MEDIUM Cross-site scripting (XSS) vulnerability in the report viewer in Crystal Enterprise 8.5, 9, and 10 allows remote attackers to inject arbitrary web script or HTML via script in the | Dec 31, 2004 | 4.3 | 18 | NO | NO |
CVE-2008-1894MEDIUM Cross-site scripting (XSS) vulnerability in desktoplaunch/InfoView/logon/logon.object in BusinessObjects InfoView XI R2 SP1, SP2, and SP3 Java version before FixPack 3.5 allows rem | Apr 18, 2008 | 4.3 | 16 | NO | NO |
CVE-2005-4813MEDIUM Unspecified vulnerability in Report Application Server (Crystalras.exe) before 11.0.0.1370, as used in Business Objects Crystal Reports XI, Crystal Reports Server XI, and BusinessO | Dec 31, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-4274MEDIUM Unspecified vulnerability in Business Objects WebIntelligence 6.5x allows remote attackers to cause a denial of service (user account lock out) via unknown attack vectors related t | Dec 15, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Businessobjects.
Media articles that mention a CVE ID that affects a product developed by Businessobjects — matched by CVE ID, not by vendor name.