« Back to list

CVE-2009-5101

Status: ModifiedMedium (5)—

Pentaho BI Server 1.7.0.1062 and earlier includes the session ID (JSESSIONID) in the URL, which allows attackers to obtain it from session history, referer headers, or sniffing of web traffic.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2009-5101",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-09-13T19:59:26.110",
  "references": [
    {
      "url": "http://antisnatchor.com/2009/06/20/pentaho-1701062-multiple-vulnerabilities/",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://jira.pentaho.com/browse/BISERVER-3245",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/507168/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://antisnatchor.com/2009/06/20/pentaho-1701062-multiple-vulnerabilities/",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://jira.pentaho.com/browse/BISERVER-3245",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/507168/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Pentaho BI Server 1.7.0.1062 and earlier includes the session ID (JSESSIONID) in the URL, which allows attackers to obtain it from session history, referer headers, or sniffing of web traffic."
    },
    {
      "lang": "es",
      "value": "Pentaho BI Server v1.7.0.1062 y anteriores incluye el identificador de sesión (JSESSIONID) en la URL, lo que permite a cualquier atacante obtener la historia de la sesión, encabezados referer, o incluso la captura de tráfico web (sniffing)."
    }
  ],
  "lastModified": "2026-06-16T23:15:01.227",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:pentaho:bi_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "605FB01C-95A9-4B46-A48A-CBCBE04FFDFA",
              "versionEndIncluding": "1.7.0.1062"
            },
            {
              "criteria": "cpe:2.3:a:pentaho:bi_server:1.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ABE602CD-9D31-4053-BAE8-078054A16A07"
            },
            {
              "criteria": "cpe:2.3:a:pentaho:bi_server:1.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "59EC974C-6F5C-4DCB-873B-F62990E1297E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}