← Vulnerability feed

Vulnerability record · CVE-2004-0204 · published 6 August 2004

CVE-2004-0204: Crystal Reports web viewer directory traversal via crystalimagehandler.aspx

Bea · Weblogic Server

The web viewers in Business Objects Crystal Reports 9 and 10 and Crystal Enterprise 9 and 10, as bundled with products such as Visual Studio .NET 2003, Outlook 2003 with Business Contact Manager, and Microsoft Business Solutions CRM 1.2, accept ".." sequences in the dynamicimag argument to crystalimagehandler.aspx. This directory traversal lets a remote attacker read and delete arbitrary files on the server. Because the affected viewers are embedded in widely deployed Microsoft and Business Objects products, the flaw exposes both report data and the underlying host filesystem.

7.5 CVSS 2.0 High EPSS 72% · top 0.6%
7.5CVSS 2.0 base score
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
18References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated remote file read and delete with public exploit code and very high EPSS, though the affected products are legacy and no KEV listing exists.

What it is

The web viewers in Business Objects Crystal Reports 9 and 10 and Crystal Enterprise 9 and 10, as bundled with products such as Visual Studio .NET 2003, Outlook 2003 with Business Contact Manager, and Microsoft Business Solutions CRM 1.2, accept ".." sequences in the dynamicimag argument to crystalimagehandler.aspx. This directory traversal lets a remote attacker read and delete arbitrary files on the server. Because the affected viewers are embedded in widely deployed Microsoft and Business Objects products, the flaw exposes both report data and the underlying host filesystem.

Impact

An unauthenticated remote attacker can read arbitrary files, exposing configuration, credential and report data, and can delete arbitrary files, causing data loss or denial of service.

Attack surface

Reached over the network through HTTP requests to crystalimagehandler.aspx with a crafted dynamicimag parameter; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.72368 (99.4th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit code exists.

What to do

  • Apply the vendor fixes referenced in Microsoft security bulletin MS04-017 and the Business Objects security bulletin from June 2004.
  • Upgrade or remove unsupported Crystal Reports 9/10 and Crystal Enterprise 9/10 web viewers that cannot be patched.
  • Restrict network access to crystalimagehandler.aspx and the Crystal web viewer components to trusted clients only.
  • Run the web viewer service with least privilege and on a host that does not hold sensitive files.
  • Validate and normalize the dynamicimag parameter, rejecting any path containing ".." sequences.

Detection

  • Inspect web server and proxy logs for requests to crystalimagehandler.aspx with dynamicimag values containing ".." or absolute paths.
  • Alert on HTTP responses from the Crystal web viewer returning unexpected file content or unusual MIME types.
  • Monitor filesystem audit logs for deletions or reads of files outside the Crystal web content directories by the web server process.
  • Search for known exploit signatures or scanner traffic targeting crystalimagehandler.aspx.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-0204 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-3257WebLogic Apache Connector mod_wl stack buffer overflow via HTTP version stringThe Apache Connector (mod_wl) in Oracle WebLogic Server 10.3 and earlier has a stack-based buffer overflow reachable through a long HTTP version stri…EPSS 84%analysed10.0CVE-2007-0417Bea weblogic server vulnerabilityBEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers …EPSS 1.8%10.0CVE-2003-0640Bea weblogic server vulnerabilityBEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and password…EPSS 2.0%10.0CVE-2001-0098BEA WebLogic Server URL buffer overflow allows remote command executionBEA WebLogic Server before 5.1.0 contains a buffer overflow reachable through a long URL beginning with a ".." string. A remote, unauthenticated atta…EPSS 78%analysed10.0CVE-2000-0681BEA WebLogic proxy plugin buffer overflow via long .JSP URLThe BEA WebLogic server proxy plugin contains a buffer overflow that is triggered by a long URL ending in a .JSP extension. A remote, unauthenticated…EPSS 51%analysed10.0CVE-2000-0684Bea weblogic server vulnerabilityBEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by di…EPSS 12%10.0CVE-2000-0685Bea weblogic server vulnerabilityBEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML …EPSS 12%9.8CVE-2005-1744Bea weblogic server vulnerabilityBEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those user…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2004-0204), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.