Vulnerability Name: | CVE-2018-2408 (CCN-141511) | ||||||||||||
Assigned: | 2017-12-15 | ||||||||||||
Published: | 2018-04-10 | ||||||||||||
Updated: | 2019-10-09 | ||||||||||||
Summary: | Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password change for a user, all other active sessions created using older password continues to be active. | ||||||||||||
CVSS v3 Severity: | 7.3 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L) 6.4 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-384 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-2408 Source: BID Type: Third Party Advisory, VDB Entry 103700 Source: CCN Type: BID-103700 SAP Business Objects CVE-2018-2408 Unspecified Session Fixation Vulnerability Source: CCN Type: SAP Security Patch Day April 2018 SAP Security Patch Day April 2018 Source: CONFIRM Type: Vendor Advisory https://blogs.sap.com/2018/04/10/sap-security-patch-day-april-2018/ Source: XF Type: UNKNOWN sap-cve20182408-weak-security(141511) Source: CCN Type: SAP Web site SAP Support Note 2537150 Source: MISC Type: Permissions Required https://launchpad.support.sap.com/#/notes/2537150 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
BACK |