CVE-2018-2442: CSRF
Published Aug 14, 2018
·Updated
In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid.
Affected Software
8 affected components
SAP BusinessObjects Business Intelligence=4.0
SAP BusinessObjects Business Intelligence=4.1
SAP BusinessObjects Business Intelligence=4.2
SAP Internet Graphics Server=7.20
SAP Internet Graphics Server=7.20ext
SAP Internet Graphics Server=7.45
SAP Internet Graphics Server=7.49
SAP Internet Graphics Server=7.53
Event History
Aug 14, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-2442?
The severity of CVE-2018-2442 is high with a severity value of 8.8.
2
Which versions of SAP BusinessObjects Business Intelligence are affected by CVE-2018-2442?
CVE-2018-2442 affects SAP BusinessObjects Business Intelligence versions 4.0, 4.1, and 4.2.
3
What is the impact of CVE-2018-2442?
CVE-2018-2442 allows an attacker to reuse user session details captured by an HTTP analysis tool in a HTML page while the user session is still valid.
4
How can I fix CVE-2018-2442?
To fix CVE-2018-2442, it is recommended to apply the necessary patches provided by SAP.
5
Where can I find more information about CVE-2018-2442?
You can find more information about CVE-2018-2442 on the following references: [1] [2] [3]