SAP Business Objects CVE-2018-2408 Unspecified Session Fixation Vulnerability
BID:103700
CVE-2018-2408 |Info
SAP Business Objects CVE-2018-2408 Unspecified Session Fixation Vulnerability
| Bugtraq ID: | 103700 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-2408 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2018 12:00AM |
| Updated: | Jul 11 2018 09:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SAP Friorified BI Launchpad 0 SAP Business Objects 4.30 SAP Business Objects 4.20 SAP Business Objects 4.10 SAP Business Objects 4.0 SAP BI LaunchPad 4.30 SAP BI LaunchPad 4.20 SAP BI LaunchPad 4.10 |
| Not Vulnerable: | |
Discussion
SAP Business Objects CVE-2018-2408 Unspecified Session Fixation Vulnerability
SAP Business Objects is prone to a unspecified session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
SAP Business Objects is prone to a unspecified session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
Exploit / POC
SAP Business Objects CVE-2018-2408 Unspecified Session Fixation Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
SAP Business Objects CVE-2018-2408 Unspecified Session Fixation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
SAP Business Objects CVE-2018-2408 Unspecified Session Fixation Vulnerability
References:
References: