Unrated severityNVD Advisory· Published Jan 10, 2001· Updated Apr 16, 2026
CVE-2001-1464
CVE-2001-1464
Description
Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords.
Affected products
1- cpe:2.3:a:businessobjects:crystal_reports:*:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.kb.cert.org/vuls/id/403307nvdExploitThird Party AdvisoryUS Government Resource
- exchange.xforce.ibmcloud.com/vulnerabilities/7928nvd
News mentions
0No linked articles in our index yet.