SAP security note 1962860, “Unauthorized Use of Application Functions in BPC 7.5”, is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can execute functions in BPC 7.5 without authentication and authorization.
Solution
Corrections have been made to the BPC Client and .NET Server applications and are available in:
- BPC 7.5 SP17
- BPC 7.53 SP08
- BPC 7.54 SP03
Corrections have also been made to ODBO SP11 to be compatible with these BPC .NET Server versions.
Reason and prerequisites
BPC Client applications (Excel client, Admin client, Server Manager, etc.) execute certain functions by referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the authenticated user. The attacker may use a cross-site scripting attack to do this, or they may present a link to the victim.
CVSS
Score 6.8 Vector: AV:N/AC:M/AU:N/C:P/I:P/A:P
References
- 1858275 – Planning and Consolidation 7.54 SP03 NetWeaver Central Note
- 1858274 – Planning and Consolidation 7.53 SP08 NetWeaver Central Note
- 1858273 – Planning and Consolidation 7.5 SP17 NetWeaver Central Note
- 1808702 – Planning and Consolidation 7.5 ODBO Client SP11 Central Note
Affected components
- SAPCPMBPCCLNT: 750 to 750
- CPM_BPC_ODBO: 100 to 100
- CPM_BPC_NW: 750 to 750
Full note on SAP: SAP Support Launchpad note 1962860
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




