SAP Security Note
Medium priority
SAP security note 1905408, "Potential denial of service in BI-RA-CR", is a note released on 11.02.2014. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can remotely exploit BI-RA-CR, rendering it, and potentially the resources that are used to serve BI-RA-CR, unavailable.
Solution
- Apply patch SP6 FP3 or SP7 (or newer) of SAP BusinessObjects XIR3.
- Alternatively, disable ActiveX support in the web browser.
Reason and prerequisites
The vulnerability gives the attacker the ability to execute arbitrary code that is part of the internal product implementation, thus allowing attacks such as Denial of Service.
CVSS
Score 8.3 Vector: AV:N/AC:M/AU:N/C:P/I:P/A:C
Affected components
- BOEWEBAPPJAVA 3.1
Full note on SAP: SAP Support Launchpad note 1905408
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
