CVE-2009-5101
Status: ModifiedMedium (5)—
Pentaho BI Server 1.7.0.1062 and earlier includes the session ID (JSESSIONID) in the URL, which allows attackers to obtain it from session history, referer headers, or sniffing of web traffic.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
- Base score: 5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.14%
- Percentile among all scored CVEs: 65
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-200
References
- http://antisnatchor.com/2009/06/20/pentaho-1701062-multiple-vulnerabilities/
- http://jira.pentaho.com/browse/BISERVER-3245
- http://www.securityfocus.com/archive/1/507168/100/0/threaded
- http://antisnatchor.com/2009/06/20/pentaho-1701062-multiple-vulnerabilities/
- http://jira.pentaho.com/browse/BISERVER-3245
- http://www.securityfocus.com/archive/1/507168/100/0/threaded
Raw JSON (NVD)
Show
{
"id": "CVE-2009-5101",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2011-09-13T19:59:26.110",
"references": [
{
"url": "http://antisnatchor.com/2009/06/20/pentaho-1701062-multiple-vulnerabilities/",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://jira.pentaho.com/browse/BISERVER-3245",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/507168/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://antisnatchor.com/2009/06/20/pentaho-1701062-multiple-vulnerabilities/",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://jira.pentaho.com/browse/BISERVER-3245",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/507168/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Pentaho BI Server 1.7.0.1062 and earlier includes the session ID (JSESSIONID) in the URL, which allows attackers to obtain it from session history, referer headers, or sniffing of web traffic."
},
{
"lang": "es",
"value": "Pentaho BI Server v1.7.0.1062 y anteriores incluye el identificador de sesión (JSESSIONID) en la URL, lo que permite a cualquier atacante obtener la historia de la sesión, encabezados referer, o incluso la captura de tráfico web (sniffing)."
}
],
"lastModified": "2026-06-16T23:15:01.227",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:pentaho:bi_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "605FB01C-95A9-4B46-A48A-CBCBE04FFDFA",
"versionEndIncluding": "1.7.0.1062"
},
{
"criteria": "cpe:2.3:a:pentaho:bi_server:1.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ABE602CD-9D31-4053-BAE8-078054A16A07"
},
{
"criteria": "cpe:2.3:a:pentaho:bi_server:1.6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "59EC974C-6F5C-4DCB-873B-F62990E1297E"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}