Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in BW-BEX, SAP security note 1800926

SAP Note 1800926

SAP security note 1800926, "Unauthorized modification of displayed content in BW-BEX". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

BW-BEX-ET-WJR is susceptible to abuse by attackers who can modify displayed content without authorization and potentially obtain authentication information from legitimate users.

  • Reflected Cross-Site Scripting (XSS) vulnerability allowing non-permanent defacement or modification of web content.
  • Theft of user authentication information, leading to potential impersonation and access to sensitive data.
  • Full compromise of application security if an administrator’s credentials are stolen.

Solution

Apply the patch provided in SAP Security Note 1802724 to address the vulnerabilities mentioned.

CVSS

Score 5.0 Vector: AV:N/AC:L/AU:N/C:N/I:P/A:N

References

Affected components

  • BI-BASE-S: Versions 7.00 to 7.31
  • SAP_BW: Versions 700 to 730
  • BIWEBAPP: Versions 7.00 to 7.31

Full note on SAP: SAP Support Launchpad note 1800926

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More