#VU125968 Session Fixation in SAP BusinessObjects Business Intelligence suite - CVE-2026-24318
Published: April 14, 2026
SAP BusinessObjects Business Intelligence suite
SAP
Description
The vulnerability allows a remote attacker to compromise another user's session.
The vulnerability exists due to insecure session management in SAP BusinessObjects Business Intelligence Platform when handling user sessions. A remote attacker can trick the victim into interacting with crafted content to compromise another user's session.