CVE-2009-5101
Estado: ModificadaMedia (5)—
Pentaho BI Server 1.7.0.1062 and earlier includes the session ID (JSESSIONID) in the URL, which allows attackers to obtain it from session history, referer headers, or sniffing of web traffic.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.14%
- Percentil entre todas las CVEs puntuadas: 65
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-200
Referencias
- http://antisnatchor.com/2009/06/20/pentaho-1701062-multiple-vulnerabilities/
- http://jira.pentaho.com/browse/BISERVER-3245
- http://www.securityfocus.com/archive/1/507168/100/0/threaded
- http://antisnatchor.com/2009/06/20/pentaho-1701062-multiple-vulnerabilities/
- http://jira.pentaho.com/browse/BISERVER-3245
- http://www.securityfocus.com/archive/1/507168/100/0/threaded
JSON original (NVD)
Mostrar
{
"id": "CVE-2009-5101",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2011-09-13T19:59:26.110",
"references": [
{
"url": "http://antisnatchor.com/2009/06/20/pentaho-1701062-multiple-vulnerabilities/",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://jira.pentaho.com/browse/BISERVER-3245",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/507168/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://antisnatchor.com/2009/06/20/pentaho-1701062-multiple-vulnerabilities/",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://jira.pentaho.com/browse/BISERVER-3245",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/507168/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Pentaho BI Server 1.7.0.1062 and earlier includes the session ID (JSESSIONID) in the URL, which allows attackers to obtain it from session history, referer headers, or sniffing of web traffic."
},
{
"lang": "es",
"value": "Pentaho BI Server v1.7.0.1062 y anteriores incluye el identificador de sesión (JSESSIONID) en la URL, lo que permite a cualquier atacante obtener la historia de la sesión, encabezados referer, o incluso la captura de tráfico web (sniffing)."
}
],
"lastModified": "2026-06-16T23:15:01.227",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:pentaho:bi_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "605FB01C-95A9-4B46-A48A-CBCBE04FFDFA",
"versionEndIncluding": "1.7.0.1062"
},
{
"criteria": "cpe:2.3:a:pentaho:bi_server:1.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ABE602CD-9D31-4053-BAE8-078054A16A07"
},
{
"criteria": "cpe:2.3:a:pentaho:bi_server:1.6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "59EC974C-6F5C-4DCB-873B-F62990E1297E"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}