SAP security note 2011395, “Potential information disclosure relating in BI-BIP-ADM”. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information relating to BI-BIP-ADM. This information could be used to allow the attacker to specialize their attacks against BI-BIP.
Solution
Install one of the following or one of their subsequent patches or support packs:
- BI 4.0 Patch 9.2
- BI 4.0 SP10
- BI 4.1 Patch 3.1
- BI 4.1 SP04
Reason and prerequisites
Audit event details can be discovered using BI-BIP-SDK. This information may be used by an attacker to further target BI-BIP.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
Full note on SAP: SAP Support Launchpad note 2011395
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
