CVE-2009-5101 Information
Feb 14, 2021
cve
Description
Pentaho BI Server 1.7.0.1062 and earlier includes the session ID (JSESSIONID) in the URL which allows attackers to obtain it from session history referer headers or sniffing of web traffic.
Reference
http://antisnatchor.com/2009/06/20/pentaho-1701062-multiple-vulnerabilities/ http://jira.pentaho.com/browse/BISERVER-3245 http://www.securityfocus.com/archive/1/507168/100/0/threaded
Share on: