Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password change for a user, all other active sessions created using older password continues to be active.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Link | Tags |
---|---|
https://blogs.sap.com/2018/04/10/sap-security-patch-day-april-2018/ | vendor advisory |
https://launchpad.support.sap.com/#/notes/2537150 | permissions required |
http://www.securityfocus.com/bid/103700 | vdb entry third party advisory |