5
CVSSv2

CVE-2009-5101

Published: 13/09/2011 Updated: 10/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Pentaho BI Server 1.7.0.1062 and previous versions includes the session ID (JSESSIONID) in the URL, which allows malicious users to obtain it from session history, referer headers, or sniffing of web traffic.

Vulnerable Product Search on Vulmon Subscribe to Product

pentaho bi server 1.2.0

pentaho bi server 1.6.0

pentaho bi server