PT-2018-15566 · Sap · Sap Businessobjects Business Intelligence
Published
2018-08-14
·
Updated
2018-10-11
·
CVE-2018-2442
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP BusinessObjects Business Intelligence versions 4.0 through 4.2
Description
The issue allows user session details to be captured by an HTTP analysis tool and reused in an HTML page while the user session is still valid, potentially leading to unauthorized access. This occurs when viewing a Web Intelligence report from BI Launchpad.
Recommendations
For versions 4.0 through 4.2, consider restricting access to sensitive reports and implementing additional session validation to minimize the risk of exploitation. As a temporary workaround, restrict the use of HTTP analysis tools to prevent session details from being captured.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Businessobjects Business Intelligence