CVE-2026-24318

Due to an Insecure session management vulnerability in SAP Business Objects Business Intelligence Platform, an unauthenticated attacker could obtain valid session tokens and reuse them to gain unauthorized access to a victim�s session. If the application continues to accept previously issued tokens after authentication, the attacker could assume the victim�s authenticated context. This could allow the attacker to access or modify information within the victim�s session scope, impacting confidentiality and integrity, while availability remains unaffected.
Configurations

No configuration.

History

14 Apr 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-14 00:16

Updated : 2026-04-17 15:18


NVD link : CVE-2026-24318

Mitre link : CVE-2026-24318

CVE.ORG link : CVE-2026-24318


JSON object : View

Products Affected

No product.

CWE
CWE-539

Use of Persistent Cookies Containing Sensitive Information