Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code injection vulnerability in BW-BEX-OT, SAP security note 1885371

SAP Note 1885371

SAP security note 1885371, "Code injection vulnerability in BW-BEX-OT", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP has released Security Note 1885371 addressing a critical code injection vulnerability in BW-BEX-OT. This vulnerability allows an attacker to execute arbitrary program code, potentially controlling system behavior or escalating privileges without having legitimate credentials.

Exploiting this vulnerability, an attacker can:

  • Inject and execute malicious code.
  • Obtain unauthorized access to sensitive information.
  • Modify or delete data.
  • Create new users with elevated privileges.
  • Perform denial of service (DoS) attacks.

Solution

Apply the appropriate Support Package for your SAP NetWeaver BW version:

For urgent cases, refer to the Correction Instructions provided in the SAP Note. Ensure you review SAP Note 1668882 before applying corrections using transaction SNOTE.

CVSS

Score 4.6 Vector: AV:N/AC:H/AU:S/C:P/I:P/A:P

Affected components

  • SAP NetWeaver BW 7.00 to 7.40
  • SAP_BW
  • SAP_BW_VIRTUAL_COMP

Full note on SAP: SAP Support Launchpad note 1885371

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More