Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to planning or consolidation transaction data, SAP security note 1939673

SAP Note 1939673

SAP security note 1939673, "Potential information disclosure relating to planning or consolidation transaction data", is a note. Below are the symptom, SAP recommended solution and affected software components.

Description

Symptom

An attacker can discover information relating to planning or consolidation transaction data in BPC NW. This information could be used to allow the attacker to specialize their attacks against planning or consolidation.

Solution

Apply the program correction instructions of this note or upgrade to the corresponding support package, so that characteristics for newly secured dimensions are automatically marked to be authorization relevant.

For existing secure dimensions, you need to manually use transaction RSA1 or RSD1 to mark the corresponding characteristics.

Reason and prerequisites

This is caused by a program error. It is only relevant for BPC NW release 10 or 10.1. Information disclosure may happen only if you have already granted an attacker necessary BW authorizations (e.g., S_RS_COMP) to access the BW objects which are generated by BPC.

CVSS

Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N

References

Affected components

  • CPMBPC: 800, 801, 810

Full note on SAP: SAP Support Launchpad note 1939673

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More