SAP security note 1694226, "Unauthorized execution of application funcs. in BW-PLA-BPS". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can execute functions in BW-PLA-BPS without authentication and authorization.
Solution
Implement this SAP Note or import the relevant Support Package.
Also, take the manual post-implementation steps into account when you implement this SAP Note.
Important: The new protection measures take effect only if the HTTPS protocol is selected for the Web interfaces before regeneration. There is no support for HTTP.
Reason and prerequisites
BW-PLA-BPS executes certain functions by referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the authenticated user. The attacker may use a cross-site scripting attack to do this, or they may present a link to the victim.
Ensure that you have implemented SAP Note 1520324 and the other SAP Notes specified there in your system or that your system has the relevant Support Package level.
Affected components
- SAP_BW (Versions 350 to 731)
- SAP_BW_VIRTUAL_COMP (Version 701)
Full note on SAP: SAP Support Launchpad note 1694226
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
