Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2408 Improper Session Management in SAP Business Objects -CMC/BI Launchpad/Fiorified BI Launchpad, SAP security note 2537150

SAP Note 2537150

SAP security note 2537150, "[CVE-2018-2408] Improper Session Management in SAP Business Objects -CMC/BI Launchpad/Fiorified BI Launchpad", is a note. Below are the symptom, CVSS score, SAP recommended solution and references.

Description

Symptom

In case of a password change for a user, all other active sessions created using the older password continue to be active.

When a user changes their password, existing active sessions established with the previous password remain active.

Solution

  • On the password change screen in the logon page, a warning message is displayed to the user informing that all active sessions will be terminated.
  • On the password change screen from the user preferences page, a warning message is displayed to the user informing that all active sessions will be terminated.
  • On successful password change, all active sessions will be terminated.

CVSS

Score 7.3 / 10 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

References

Full note on SAP: SAP Support Launchpad note 2537150

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More