• Sign in

CVE-2009-5101

    CVE-2009-5101  
Description Pentaho BI Server 1.7.0.1062 and earlier includes the session ID (JSESSIONID) in the URL, which allows attackers to obtain it from session history, referer headers, or sniffing of web traffic.
Impact
  CVSS v2 : 5 MEDIUM  
Type
  CWE-200  
Attack Vector
CVSSv2 Vector : AV:N/AC:L/Au:N/C:P/I:N/A:N
Quick linksCVE, NVD, CERT, Metasploit, Exploit-db, Fulldisc, Bugtraq, Microsoft, Red Hat, Debian, GitHub code/issues, Google
References
http://antisnatchor.com/2009/06/20/pentaho-1701062-multiple-vulnerabilities/
http://jira.pentaho.com/browse/BISERVER-3245
http://www.securityfocus.com/archive/1/507168/100/0/threaded
  • FAQ
  • Terms of service
  • Privacy policy