SAP security note 1966896, "Missing authorization check in BW-BEX-OT". Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can access functions in BW-BEX-OT that should have restricted access, potentially leading to an escalation of privileges.
Solution
To resolve this issue, import the appropriate Support Package for your SAP NetWeaver BW version:
- SAP NetWeaver BW 7.00: import Support Package 33 (SAPKW70033) once SAP Note 1930762 is released.
- SAP NetWeaver BW 7.01 (EHP 1): import Support Package 16 (SAPKW70116) once SAP Note 1936601 is released.
- SAP NetWeaver BW 7.02 (EHP 2): import Support Package 16 (SAPKW70216) once SAP Note 1940530 is released.
- SAP NetWeaver BW 7.11: import Support Package 14 (SAPKW71114) once SAP Note 1940531 is released.
- SAP NetWeaver BW 7.30: import Support Package 12 (SAPKW73012) once SAP Note 1950117 is released.
- SAP NetWeaver BW 7.31 (EnhP 1): import Support Package 12 (SAPKW73112) once SAP Note 1951409 is released.
Additionally, follow the correction instructions provided in the note. Ensure you check SAP Note 1668882 using transaction SNOTE before applying any corrections. This note may be available prior to the Support Package release, although it may still indicate a “preliminary version.”
Reason and prerequisites
BW-BEX-OT lacks proper authorization checks for certain functions, resulting in unintended system behavior.
Full note on SAP: SAP Support Launchpad note 1966896
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
