CVE-2009-5101
N/A
N/A
Summary
Pentaho BI Server 1.7.0.1062 and earlier includes the session ID (JSESSIONID) in the URL, which allows attackers to obtain it from session history, referer headers, or sniffing of web traffic.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://antisnatchor.com/2009/06/20/pentaho-1701062-multiple-vulnerabilities/
- http://www.securityfocus.com/archive/1/507168/100/0/threaded
- http://jira.pentaho.com/browse/BISERVER-3245
References
- http://antisnatchor.com/2009/06/20/pentaho-1701062-multiple-vulnerabilities/
- http://www.securityfocus.com/archive/1/507168/100/0/threaded
- http://jira.pentaho.com/browse/BISERVER-3245
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.