CVE-2018-2442: SAP Businessobjects Business Intelligence

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid.

Affected products

  • SAP Businessobjects Business Intelligence: version 4.0 only; version 4.1 only; version 4.2 only
  • SAP Internet Graphics Server: version 7.20 only; version 7.20ext only; version 7.45 only; version 7.49 only; version 7.53 only

Published 2018-08-14. Last modified 2026-06-17.