PT-2006-4942 · Business Objects · Business Objects Crystal Enterprise
Publicado
2006-11-29
·
Atualizado
2017-07-20
·
CVE-2006-4099
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Business Objects Crystal Enterprise versions 9 through 10
Description
The issue allows remote attackers to hijack sessions of other users due to the generation of predictable session identifiers. This is achieved via WCSID cookie values.
Recommendations
For Business Objects Crystal Enterprise versions 9 through 10, consider regenerating session identifiers with improved randomness to prevent predictability and potential session hijacking. As a temporary workaround, restrict access to sensitive operations that rely on session identifiers to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Business Objects Crystal Enterprise