SAP security note 1800926, "Unauthorized modification of displayed content in BW-BEX". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
BW-BEX-ET-WJR is susceptible to abuse by attackers who can modify displayed content without authorization and potentially obtain authentication information from legitimate users.
- Reflected Cross-Site Scripting (XSS) vulnerability allowing non-permanent defacement or modification of web content.
- Theft of user authentication information, leading to potential impersonation and access to sensitive data.
- Full compromise of application security if an administrator’s credentials are stolen.
Solution
Apply the patch provided in SAP Security Note 1802724 to address the vulnerabilities mentioned.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:N/I:P/A:N
References
- SAP Security Note 1802724 – Replacement for this obsolete note.
- SAP Security Note 1788142 – NW7.0 SPS 28 Patch 10 note for BI Java.
Affected components
- BI-BASE-S: Versions 7.00 to 7.31
- SAP_BW: Versions 700 to 730
- BIWEBAPP: Versions 7.00 to 7.31
Full note on SAP: SAP Support Launchpad note 1800926
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
