SAP security note 1886051, "Code injection vulnerability in BW-BEX-OT-DBIF". Below are the symptom and SAP recommended solution.
Description
Symptom
BW-BEX-OT-DBIF contains code that permits the execution of arbitrary program code of the user’s choice. An attacker can control the behavior of the system or potentially escalate privileges by executing malicious code without possessing legitimate credentials.
Solution
To address this vulnerability, import the appropriate Support Package for your SAP NetWeaver BW version as outlined below. The Support Packages will be available once the corresponding SAP Notes are released.
- SAP NetWeaver BW 7.00: import Support Package 33 (SAPKW70033), see SAP Note 1930762 – “SAPBWNews NW BW 7.0 ABAP SP33”.
- SAP NetWeaver BW 7.01 (EHP 1): import Support Package 16 (SAPKW70116), see SAP Note 1936601 – “SAPBINews NW7.01 BW ABAP SP16”.
- SAP NetWeaver BW 7.02 (EHP 2): import Support Package 16 (SAPKW70216), see SAP Note 1940530 – “Preliminary Version SAPBWNews NW BW 7.02 ABAP SP16”.
- SAP NetWeaver BW 7.11: import Support Package 14 (SAPKW71114), see SAP Note 1940531 – “Preliminary Version SAPBINews NW7.11 BW ABAP SP14”.
- SAP NetWeaver BW 7.30: import Support Package 12 (SAPKW73012), see SAP Note 1950117 – “SAPBWNews NW7.30 BW ABAP SP12”.
- SAP NetWeaver BW 7.31 (EHP 1): import Support Package 12 (SAPKW73112), see SAP Note 1951409 – “Preliminary Version SAPBWNews NW BW 7.31/7.03 ABAP SP12”.
- SAP NetWeaver BW 7.40: import Support Package 7 (SAPKW74007), see SAP Note 1955499 – “Preliminary Version SAPBWNews NW BW 7.4 ABAP SP07”.
Before applying the correction instructions, review SAP Note 1668882 using transaction SNOTE. This note might be available prior to the release of the Support Package, although it may still be labeled as a “preliminary version.”
CVSS
Score 4.6 Vector: AV:N/AC:H/AU:S/C:P/I:P/A:P
Full note on SAP: SAP Support Launchpad note 1886051
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
