VYPR
High severity7.3NVD Advisory· Published Apr 10, 2018· Updated Jun 17, 2026

CVE-2018-2408

CVE-2018-2408

Description

Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password change for a user, all other active sessions created using older password continues to be active.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:sap:businessobjects:4.0:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:sap:businessobjects:4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:businessobjects:4.10:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:businessobjects:4.20:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:businessobjects:4.30:*:*:*:*:*:*:*
    • (no CPE)range: >=4.0, <=4.30
  • SAP SE/SAP Business Objectsv5
    Range: 4.00

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.