PT-2006-4942 · Business Objects · Business Objects Crystal Enterprise

Publicado

2006-11-29

·

Atualizado

2017-07-20

·

CVE-2006-4099

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Business Objects Crystal Enterprise versions 9 through 10
Description The issue allows remote attackers to hijack sessions of other users due to the generation of predictable session identifiers. This is achieved via WCSID cookie values.
Recommendations For Business Objects Crystal Enterprise versions 9 through 10, consider regenerating session identifiers with improved randomness to prevent predictability and potential session hijacking. As a temporary workaround, restrict access to sensitive operations that rely on session identifiers to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4099

Produtos afetados

Business Objects Crystal Enterprise