SAP Business Objects Business Intelligence Platform Insecure Session Management Vulnerability

Vulnerability

An insecure session management vulnerability exists in SAP Business Objects Business Intelligence Platform. This vulnerability allows an unauthenticated attacker to obtain and reuse valid session tokens, potentially gaining unauthorized access to a victim's session. If the application accepts previously issued tokens after authentication, the attacker could exploit this to access or modify information within the victim's session, thereby impacting confidentiality and integrity.

Impact

Exploitation of this vulnerability could lead to unauthorized access to a user's session, allowing an attacker to access or modify information within that session's scope.

Remediation

Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform.

Added: Apr 14, 2026, 12:29 AM
Updated: Apr 14, 2026, 12:29 AM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
1.3
exploitability
7.4
remediation
0.0
relevance
5.9
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.