Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential denial of service in BI-RA-CR, SAP security note 1905408

SAP Note 1905408
SAP Security Note
Medium priority

SAP security note 1905408, "Potential denial of service in BI-RA-CR", is a note released on 11.02.2014. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBusiness intelligence solutions > Business intelligence platform > Obsolete; BI-DEV-JAV, BI-DEV-NET-SDK, BI-DEV-WEB (BI-BIP-SDK)
PriorityCorrection with medium priority
TypeSAP Security Note
StatusReleased for Customer
Released on11.02.2014

Description

Symptom

An attacker can remotely exploit BI-RA-CR, rendering it, and potentially the resources that are used to serve BI-RA-CR, unavailable.

Solution

  • Apply patch SP6 FP3 or SP7 (or newer) of SAP BusinessObjects XIR3.
  • Alternatively, disable ActiveX support in the web browser.

Reason and prerequisites

The vulnerability gives the attacker the ability to execute arbitrary code that is part of the internal product implementation, thus allowing attacks such as Denial of Service.

CVSS

Score 8.3 Vector: AV:N/AC:M/AU:N/C:P/I:P/A:C

Affected components

  • BOEWEBAPPJAVA 3.1

Full note on SAP: SAP Support Launchpad note 1905408

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More