First published: Tue Aug 14 2018(Updated: )
In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | =4.0 | |
SAP BusinessObjects Business Intelligence | =4.1 | |
SAP BusinessObjects Business Intelligence | =4.2 | |
SAP internet Graphics Server | =7.20 | |
SAP internet Graphics Server | =7.20ext | |
SAP internet Graphics Server | =7.45 | |
SAP internet Graphics Server | =7.49 | |
SAP internet Graphics Server | =7.53 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-2442 is high with a severity value of 8.8.
CVE-2018-2442 affects SAP BusinessObjects Business Intelligence versions 4.0, 4.1, and 4.2.
CVE-2018-2442 allows an attacker to reuse user session details captured by an HTTP analysis tool in a HTML page while the user session is still valid.
To fix CVE-2018-2442, it is recommended to apply the necessary patches provided by SAP.
You can find more information about CVE-2018-2442 on the following references: [1] [2] [3]