Title: Business Objects Crystal Enterprise Report File Cross-Site Scripting Vulnerability
Severity: MODERATE
Description:
Business Objects Crystal Enterprise is an application that allows for dynamic generation of reports. It is available for numerous platforms including Microsoft Windows, IBM AIX, Sun Solaris, HP-UX, and Linux.
Business Objects Crystal Enterprise is prone to a cross-site scripting vulnerability. The source of the vulnerability is that input supplied in URIs to Report (RPT) files is not adequately sanitized before being output in dynamically generated pages.
An attacker could exploit this issue by enticing a user to following a malicious link to a Report file. Malicious script embedded in the link could access properties of the vulnerable Crystal Enterprise site, allowing for various attacks such as theft of cookie-based authentication credentials.
Affected Products:
- Business Objects Crystal Enterprise 10.0.0
- Business Objects Crystal Enterprise 8.5.0
- Business Objects Crystal Enterprise 9.0.0
References:
- Business Objects: URL to a RPT file may expose client-side source information with a script tag
- Business Objects: Vendor Homepage
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.