← Back to CVEs
CVE-2001-1464
N/ADescription
Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords.
CVE Details
CVSS v3.1 ScoreN/A
Published1/10/2001
Last Modified4/3/2025
Sourcenvd
Honeypot Sightings0
Affected Products
businessobjects:crystal_reports
References
http://www.kb.cert.org/vuls/id/403307(cve@mitre.org)
https://exchange.xforce.ibmcloud.com/vulnerabilities/7928(cve@mitre.org)
http://www.kb.cert.org/vuls/id/403307(af854a3a-2127-422b-91ae-364da2661108)
https://exchange.xforce.ibmcloud.com/vulnerabilities/7928(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.