Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in BW-BEX-ET, SAP security note 1607845

SAP Note 1607845
SAP Security Note
High priority

SAP security note 1607845, "Unauthorized modification of displayed content in BW-BEX-ET", released on 13.09.2011. Below are the symptom and SAP recommended solution.

ComponentSAP Business Warehouse > Business Explorer > Enduser Technology
PriorityCorrection with high priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on13.09.2011

Description

Symptom

The BW-BEX could be abused by a malicious user, who could modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.

Solution

SAP NetWeaver BW 7.00: Import Support Package 28 for SAP NetWeaver BW 7.00 (SAPKW70028) into your BW system. The Support Package will be available as soon as note 1600222 with the short text "SAPBWNews NW BW 7.0 ABAP SP28", which describes this Support Package in more detail, is released for customers.

SAP NetWeaver BW 7.01 (SAP NW BW7.0 EnhP 1): Import Support Package 11 for SAP NetWeaver BW 7.01 (SAPKW70111) into your BW system. The Support Package will be available as soon as note 1601974 with the short text "SAPBINews NW7.01 BW ABAP SP11", which describes this Support Package in more detail, is released for customers.

SAP NetWeaver BW 7.02 (SAP NW BW7.0 EnhP 2): Import Support Package 10 for SAP NetWeaver BW 7.02 (SAPKW70210) into your BW system. The Support Package will be available as soon as note 1604436 with the short text "Prelimenary Version SAPBWNews NW BW 7.02 ABAP SP10", which describes this Support Package in more detail, is released for customers.

SAP NetWeaver BW 7.11: Import Support Package 08 for SAP NetWeaver BW 7.11 (SAPKW71108) into your BW system. The Support Package will be available as soon as SAP note 1510977 with the short text "Prelimenary Version SAPBINews NW7.11 BW ABAP SP8", which describes this Support Package in more detail, is released for customers.

SAP NetWeaver BW 7.30: Import Support Package 05 for SAP NetWeaver BW 7.30 (SAPKW73005) into your BW system. The Support Package will be available as soon as note 1606526 with the short text "SAPBWNews NW7.30 BW ABAP SP05", which describes this Support Package in more detail, is released for customers.

SAP NetWeaver BW 7.31 (SAP NW BW7.0 EnhP 3): Import Support Package 1 for SAP NetWeaver BW 7.31 (SAPKW73101) into your BW system. The Support Package will be available as soon as note 1593298 with the short text "Prelimenary Version SAPBWNews NW BW 7.31/7.03 ABAP SP1", which describes this Support Package in more detail, is released for customers.

You can use the correction instructions to implement correction before the Support Package. Beforehand, definitely check SAP Note 875986 for transaction SNOTE.

This note might already be available before the Support Package is released. In this case, however, the short text still contains the terms "preliminary version".

Reason and prerequisites

Pages within the BW-BEX do not sufficiently encode OUTPUT parameters, resulting in a reflected cross-site scripting issue. A reflected cross-site scripting attack can be used to non-permanently deface or modify displayed content from a website.

Reflected cross-site scripting can be used to steal another user’s authentication information, such as data relating to their current session. An attacker who gains access to this data could use it to impersonate the user and access all information with the same rights as the target user. If an administrator is impersonated, the application’s security could be fully compromised.

Full note on SAP: SAP Support Launchpad note 1607845

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More