PT-2004-1643 · Sap · Sap Business Objects Web Intelligence

Publicado

2004-12-31

·

Atualizado

2017-07-11

·

CVE-2004-0533

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Business Objects WebIntelligence versions 2.7.0 through 2.7.4
Description The issue allows remote authenticated users to delete arbitrary files on the server by sending a crafted delete request using the InfoView web client, due to the software only enforcing access controls on the client.
Recommendations For versions 2.7.0 through 2.7.4, consider restricting access to the delete request functionality in the InfoView web client until a patch is available. As a temporary workaround, limit the privileges of authenticated users to prevent them from deleting arbitrary files on the server.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-0533

Produtos afetados

Sap Business Objects Web Intelligence