In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid.
2018-08-14T16:29:00.677
2024-11-21T04:03:49.367
Modified
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | sap | businessobjects_business_intelligence | 4.0 | Yes |
| Application | sap | businessobjects_business_intelligence | 4.1 | Yes |
| Application | sap | businessobjects_business_intelligence | 4.2 | Yes |
| Application | sap | internet_graphics_server | 7.20 | Yes |
| Application | sap | internet_graphics_server | 7.20ext | Yes |
| Application | sap | internet_graphics_server | 7.45 | Yes |
| Application | sap | internet_graphics_server | 7.49 | Yes |
| Application | sap | internet_graphics_server | 7.53 | Yes |