Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2998 articles · 110798 vulns · 36/41 feeds (7d)
← Back to list
4.2
CVE-2026-24318
sap · sap businessobjects business intelligence platform

Insecure Session Management vulnerability in SAP BusinessObjects Business Intelligence Platform

Description

Due to an Insecure session management vulnerability in SAP Business Objects Business Intelligence Platform, an unauthenticated attacker could obtain valid session tokens and reuse them to gain unauthorized access to a victim�s session. If the application continues to accept previously issued tokens after authentication, the attacker could assume the victim�s authenticated context. This could allow the attacker to access or modify information within the victim�s session scope, impacting confidentiality and integrity, while availability remains unaffected.

Affected Products

VendorProductVersions
sapsap businessobjects business intelligence platformENTERPRISE 430, 2025, 2027

References

  • https://me.sap.com/notes/3702191
  • https://url.sap/sapsecuritypatchday

Related News (2 articles)

Tier B
CCCS Canada7h ago
SAP security advisory – April 2026 monthly rollup (AV26-349)
→ No new info (linked only)
Tier C
VulDB15h ago
CVE-2026-24318 | SAP BusinessObjects Business Intelligence Platform 2025/2027/ENTERPRISE 430 persistent cookies containing sensitive information
→ No new info (linked only)
CVSS 3.14.2 MEDIUM
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
CWECWE-539
PublishedApr 14, 2026
Last enriched15h agov2
Trending Score34
Source articles2
Independent2
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-27681EXP
SQL Injection vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse
Trending: 67
MEDIUMCVE-2026-27674EXP
Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java)
Trending: 44
MEDIUMCVE-2026-27683EXP
Reflected cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform
Trending: 40
LOWCVE-2026-27675EXP
Code Injection vulnerability in SAP Landscape Transformation
Trending: 38
HIGHCVE-2026-34256
Missing Authorization check in SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise)
Trending: 37

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 14, 2026
Discovered by ZDM
Apr 14, 2026
Updated: description, severity
Apr 14, 2026

Version History

v2
Last enriched 15h ago
v2Tier C15h ago

Updated description with new details about persistent cookies and changed severity to HIGH.

descriptionseverity
via VulDB
v121h ago

Initial creation