Total vulnerabilities in the database
In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid.
Software | From | Fixed in |
---|---|---|
sap / businessobjects_business_intelligence | 4.2 | 4.2.x |
sap / businessobjects_business_intelligence | 4.1 | 4.1.x |
sap / businessobjects_business_intelligence | 4.0 | 4.0.x |
sap / internet_graphics_server | 7.20 | 7.20.x |
sap / internet_graphics_server | 7.20ext | 7.20ext.x |
sap / internet_graphics_server | 7.45 | 7.45.x |
sap / internet_graphics_server | 7.49 | 7.49.x |
sap / internet_graphics_server | 7.53 | 7.53.x |