PT-2018-15566 · Sap · Sap Businessobjects Business Intelligence

Publicado

2018-08-14

·

Atualizado

2018-10-11

·

CVE-2018-2442

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP BusinessObjects Business Intelligence versions 4.0 through 4.2
Description The issue allows user session details to be captured by an HTTP analysis tool and reused in an HTML page while the user session is still valid, potentially leading to unauthorized access. This occurs when viewing a Web Intelligence report from BI Launchpad.
Recommendations For versions 4.0 through 4.2, consider restricting access to sensitive reports and implementing additional session validation to minimize the risk of exploitation. As a temporary workaround, restrict the use of HTTP analysis tools to prevent session details from being captured.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-2442

Produtos afetados

Sap Businessobjects Business Intelligence