Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in BW-BEX-OT, SAP security note 1847217

SAP Note 1847217
SAP Security Note
High priority

SAP security note 1847217, “Missing authorization check in BW-BEX-OT”, is a note released on 13.08.2013. Below are the symptom and SAP recommended solution.

ComponentSAP Business Warehouse > Business Explorer > OLAP Technology
PriorityHigh priority
TypeSAP Security Note
StatusReleased for Customer
Released on13.08.2013

Description

Symptom

An authenticated user can use functions of BW-BEX-OT to which access should be restricted. This may result in an escalation of privileges.

Solution

Depending on your SAP NetWeaver BW version, import the corresponding Support Package:

Additionally, refer to SAP Note 1668882 for information about transaction SNOTE.

Reason and prerequisites

BW-BEX-OT does not contain authorization checks for verifying an authenticated user’s access to certain functions. This may lead to undesired system behavior.

CVSS

Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P

Full note on SAP: SAP Support Launchpad note 1847217

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More