PT-2006-4942 · Business Objects · Business Objects Crystal Enterprise
Published
2006-11-29
·
Updated
2017-07-20
·
CVE-2006-4099
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Business Objects Crystal Enterprise versions 9 through 10
Description
The issue allows remote attackers to hijack sessions of other users due to the generation of predictable session identifiers. This is achieved via WCSID cookie values.
Recommendations
For Business Objects Crystal Enterprise versions 9 through 10, consider regenerating session identifiers with improved randomness to prevent predictability and potential session hijacking. As a temporary workaround, restrict access to sensitive operations that rely on session identifiers to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Business Objects Crystal Enterprise