CVE-2018-2442

HIGH

SAP BusinessObjects Business Intelligence 4.0-4.2 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid.

References (3)

Core 3
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2407193
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105078

Scores

CVSS v3 8.8
EPSS 0.0017
EPSS Percentile 37.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (8)
sap/businessobjects_business_intelligence 4.0
sap/businessobjects_business_intelligence 4.1
sap/businessobjects_business_intelligence 4.2
sap/internet_graphics_server 7.20
sap/internet_graphics_server 7.20ext
sap/internet_graphics_server 7.45
sap/internet_graphics_server 7.49
sap/internet_graphics_server 7.53
Published Aug 14, 2018
Tracked Since Feb 18, 2026