Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 14 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap Se
Sap Se sap Business Objects Business Intelligence Platform |
|
| Vendors & Products |
Sap Se
Sap Se sap Business Objects Business Intelligence Platform |
Tue, 14 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to an Insecure session management vulnerability in SAP Business Objects Business Intelligence Platform, an unauthenticated attacker could obtain valid session tokens and reuse them to gain unauthorized access to a victim�s session. If the application continues to accept previously issued tokens after authentication, the attacker could assume the victim�s authenticated context. This could allow the attacker to access or modify information within the victim�s session scope, impacting confidentiality and integrity, while availability remains unaffected. | |
| Title | Insecure Session Management vulnerability in SAP BusinessObjects Business Intelligence Platform | |
| Weaknesses | CWE-539 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-04-14T13:14:19.302Z
Reserved: 2026-01-21T22:15:25.361Z
Link: CVE-2026-24318
Updated: 2026-04-14T13:09:26.872Z
Status : Awaiting Analysis
Published: 2026-04-14T00:16:04.913
Modified: 2026-04-17T15:18:16.507
Link: CVE-2026-24318
No data.
OpenCVE Enrichment
Updated: 2026-04-14T16:31:32Z