CVE-2026-24318CWE-539

Insecure Session Management vulnerability in SAP BusinessObjects Business Intelligence Platform

Medium · published April 14, 2026

CVSS v3.1
4.2
EPSS
0%
Percentile
6.2
In the wild
Unconfirmed
What it is

Due to an Insecure session management vulnerability in SAP Business Objects Business Intelligence Platform, an unauthenticated attacker could obtain valid session tokens and reuse them to gain unauthorized access to a victim�s session. If the application continues to accept previously issued tokens after authentication, the attacker could assume the victim�s authenticated context. This could allow the attacker to access or modify information within the victim�s session scope, impacting confidentiality and integrity, while availability remains unaffected.

The record
Technical detail
CVSS v3.1
4.2 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00167 · 6.2th percentile
Weakness
CWE-539 · Use of Persistent Cookies Containing Sensitive Information
Published
2026-04-14T00:06Z
EPSS history
Timeline
  • 14 APR 00:06Z
    Insecure Session Management vulnerability in SAP BusinessObjects Business Intelligence Platform
    cvelistv5