SAP Security Note
High priority
SAP security note 1847217, “Missing authorization check in BW-BEX-OT”, is a note released on 13.08.2013. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of BW-BEX-OT to which access should be restricted. This may result in an escalation of privileges.
Solution
Depending on your SAP NetWeaver BW version, import the corresponding Support Package:
- SAP NetWeaver BW 7.00: Import Support Package 31 (SAPKW70031)
- SAP NetWeaver BW 7.01: Import Support Package 14 (SAPKW70114)
- SAP NetWeaver BW 7.02: Import Support Package 14 (SAPKW70214)
- SAP NetWeaver BW 7.11: Import Support Package 12 (SAPKW71112)
- SAP NetWeaver BW 7.30: Import Support Package 10 (SAPKW73010)
- SAP NetWeaver BW 7.31: Import Support Package 8 (SAPKW73108)
- SAP NetWeaver BW 7.40: Import Support Package 3 (SAPKW74003)
Additionally, refer to SAP Note 1668882 for information about transaction SNOTE.
Reason and prerequisites
BW-BEX-OT does not contain authorization checks for verifying an authenticated user’s access to certain functions. This may lead to undesired system behavior.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
Full note on SAP: SAP Support Launchpad note 1847217
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
