Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential remote code execution in BW WAD, SAP security note 1546601

SAP Note 1546601

SAP security note 1546601, "Potential remote code execution in BW WAD". Below are the symptom and SAP recommended solution.

Description

Symptom

A malicious user can exploit BW WAD to enable them to take complete control of the product, including viewing, changing, or deleting data.

Solution

SAP NetWeaver 7.0 BW Front End for GUI 710: Import Front-End Patch (FEP) 1500 (or higher) for SAP NetWeaver 7.x BW Front End (bi710sp15_1500-10004472.exe) into your system. The FEP will be available as soon as SAP Note 1413032 with the short text "SAPBWNews NW 7.x BW Add-On Frontend Patch 1500 – GUI 7.10", which describes this FEP in more detail, is released for customers.

You can check the planned availability dates in the attached SAP Note 1085218.

SAP NetWeaver 7.0 BW Front End for GUI 720: Import Front-End Patch (FEP) 400 (or higher) for SAP NetWeaver 7.x BW Front End (bi720sp4_400-10004472.exe) into your system. The FEP will be available as soon as SAP Note 1435815 with the short text "SAPBWNews NW 7.x BW Add-On Frontend Patch 400 – GUI 7.20", which describes this FEP in more detail, is released for customers.

You can check the planned availability dates in the attached SAP Note 1085218.

This SAP Note might already be available before the FEP is released. In this case, however, the short text still contains the terms "preliminary version".

Reason and prerequisites

A buffer overflow vulnerability exists in BW WAD. This enables a malicious user to inject code into the working memory that is subsequently executed by the application. It can also be used to cause a general fault in the product, thereby producing a termination of the product.

CVSS

Score 4.4 Vector: AV:L/AC:M/AU:N/C:P/I:P/A:P

Full note on SAP: SAP Support Launchpad note 1546601

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More