Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password change for a user, all other active sessions created using older password continues to be active.
2018-04-10T15:29:01.427
2024-11-21T04:03:45.860
Modified
CVSSv3.0: 7.3 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | sap | businessobjects | 4.0 | Yes |
| Application | sap | businessobjects | 4.10 | Yes |
| Application | sap | businessobjects | 4.20 | Yes |
| Application | sap | businessobjects | 4.30 | Yes |