HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2018-2408

CVSS 7.3v3.0pub. 2018-04-10upd. 2024-11-21

Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password change for a user, all other active sessions created using older password continues to be active.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
  • Sap Businessobjects

    APP
    Sap
    4.04.104.204.30
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2019-0259CRITICAL9.8PL ✓same product

SAP BusinessObjects — nieograniczony upload plików w Visual Difference

CVE-2022-28214HIGH7.8same product

During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authe...

CVE-2019-0289HIGH7.1same product

Under certain conditions SAP BusinessObjects Business Intelligence platform (Analysis for OLAP), versions 4.2 ...

CVE-2019-0287HIGH7.6same product

Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versi...

CVE-2015-7730HIGH10.0same product

SAP BusinessObjects BI Platform 4.1, BusinessObjects Edge 4.0, and BusinessObjects XI (BOXI) 3.1 R3 allow remo...