CVE-2006-4099

Business Objects Crystal Enterprise 9 and 10 generates predictable session identifiers, which allows remote attackers to hijack sessions of other users via WCSID cookie values.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:businessobjects:crystal_enterprise:9:*:*:*:*:*:*:*
cpe:2.3:a:businessobjects:crystal_enterprise:10:*:*:*:*:*:*:*

History

No history.

Information

Published : 2006-11-29 17:28

Updated : 2023-12-10 10:40


NVD link : CVE-2006-4099

Mitre link : CVE-2006-4099

CVE.ORG link : CVE-2006-4099


JSON object : View

Products Affected

businessobjects

  • crystal_enterprise