CVE-2009-5101
CVE-2009-5101 | |
Description | Pentaho BI Server 1.7.0.1062 and earlier includes the session ID (JSESSIONID) in the URL, which allows attackers to obtain it from session history, referer headers, or sniffing of web traffic. |
Impact |
CVSS v2 : 5 MEDIUM
|
Type | |
Attack Vector |
CVSSv2 Vector : AV:N/AC:L/Au:N/C:P/I:N/A:N |
Quick links | CVE, NVD, CERT, Metasploit, Exploit-db, Fulldisc, Bugtraq, Microsoft, Red Hat, Debian, GitHub code/issues, Google |
References |