PT-2006-4942 · Business Objects · Business Objects Crystal Enterprise

Published

2006-11-29

·

Updated

2017-07-20

·

CVE-2006-4099

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Business Objects Crystal Enterprise versions 9 through 10
Description The issue allows remote attackers to hijack sessions of other users due to the generation of predictable session identifiers. This is achieved via WCSID cookie values.
Recommendations For Business Objects Crystal Enterprise versions 9 through 10, consider regenerating session identifiers with improved randomness to prevent predictability and potential session hijacking. As a temporary workaround, restrict access to sensitive operations that rely on session identifiers to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4099

Affected Products

Business Objects Crystal Enterprise