CVE-2018-2442
14.08.2018, 16:29
In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid.
| Vendor | Product | Version |
|---|---|---|
| sap | businessobjects_business_intelligence | 4.0 |
| sap | businessobjects_business_intelligence | 4.1 |
| sap | businessobjects_business_intelligence | 4.2 |
| sap | internet_graphics_server | 7.20 |
| sap | internet_graphics_server | 7.20ext:ext |
| sap | internet_graphics_server | 7.45 |
| sap | internet_graphics_server | 7.49 |
| sap | internet_graphics_server | 7.53 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References