Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords.
References
Link Resource
http://www.kb.cert.org/vuls/id/403307 Exploit Third Party Advisory US Government Resource
https://exchange.xforce.ibmcloud.com/vulnerabilities/7928
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2005-04-21T04:00:00

Updated: 2017-07-10T14:57:01

Reserved: 2005-04-21T00:00:00


Link: CVE-2001-1464

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2001-01-10T05:00:00.000

Modified: 2017-07-11T01:29:08.663


Link: CVE-2001-1464

JSON object: View

cve-icon Redhat Information

No data.