CVE-2001-1464

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/01/2001
Last modified:
03/04/2025

Description

Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:businessobjects:crystal_reports:*:*:*:*:*:*:*:*