5
CVE-2009-5101
- EPSS 1.14%
- Veröffentlicht 13.09.2011 19:59:26
- Zuletzt bearbeitet 16.06.2026 23:15:01
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Pentaho BI Server 1.7.0.1062 and earlier includes the session ID (JSESSIONID) in the URL, which allows attackers to obtain it from session history, referer headers, or sniffing of web traffic.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.14% | 0.623 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://antisnatchor.com/2009/06/20/pentaho-1701062-multiple-vulnerabilities/
http://www.securityfocus.com/archive/1/507168/100/0/threaded
http://jira.pentaho.com/browse/BISERVER-3245