In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://launchpad.support.sap.com/#/notes/2407193 | vendor advisory permissions required |
http://www.securityfocus.com/bid/105078 | third party advisory vdb entry |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499352742 | vendor advisory |