SAP security note 2537150, "[CVE-2018-2408] Improper Session Management in SAP Business Objects -CMC/BI Launchpad/Fiorified BI Launchpad", is a note. Below are the symptom, CVSS score, SAP recommended solution and references.
Description
Symptom
In case of a password change for a user, all other active sessions created using the older password continue to be active.
When a user changes their password, existing active sessions established with the previous password remain active.
Solution
- On the password change screen in the logon page, a warning message is displayed to the user informing that all active sessions will be terminated.
- On the password change screen from the user preferences page, a warning message is displayed to the user informing that all active sessions will be terminated.
- On successful password change, all active sessions will be terminated.
CVSS
Score 7.3 / 10 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
References
Full note on SAP: SAP Support Launchpad note 2537150
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
