CVE-2003-1249: High severity BusinessObjects Webintelligence vulnerability
Published Dec 31, 2003
·Updated
WebIntelligence 2.7.1 uses guessable user session cookies, which allows remote attackers to hijack sessions.
Affected Software
1 affected component
BusinessObjects Webintelligence=2.7.1
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Nov 16, 2005
CVE Published
via MITRE·12:37 PM
Data Sourced
via MITRE·12:37 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1249?
CVE-2003-1249 is considered to have a high severity due to the potential for session hijacking.
2
How do I fix CVE-2003-1249?
To fix CVE-2003-1249, ensure that session cookies are configured with proper security attributes like HttpOnly and Secure.
3
What systems are affected by CVE-2003-1249?
CVE-2003-1249 specifically affects SAP BusinessObjects Web Intelligence version 2.7.1.
4
What type of attack does CVE-2003-1249 enable?
CVE-2003-1249 enables attackers to hijack user sessions through guessable session cookies.
5
Is CVE-2003-1249 still a threat today?
While CVE-2003-1249 is an older vulnerability, it could still pose a threat if the affected software is used in unpatched environments.