Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

BEx Web Removing DEBUG=X parameter for non-admin users, SAP security note 1542355

SAP Note 1542355

SAP security note 1542355, “BEx Web: Removing DEBUG=X parameter for non-admin users”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

You have used the BEx URL parameter DEBUG=X to analyze command processing of BEx Web Applications. This parameter was influencing the processing by adding additional debug messages with information that could be used to analyze the commands (e.g., path statements processing).

Some internal information was given to the user. Such information, even if not directly providing data to the user, could be incorrectly used to analyze the system’s behavior.

Solution

Usage of the DEBUG parameter by non-administrator users is not allowed. Such a parameter in the URL will be ignored.

If you still want to analyze the processing of web applications during design, consult your administrator to apply this setting as described in note 1128976.

  • All users without administrator permissions cannot use the DEBUG=X parameter via URL. Administrator users still can.
  • Analysis of internal processing is not possible, even if BEx documentation states that the DEBUG=X parameter can be used. Corresponding documentation will be updated with some delay.

Reason and prerequisites

Potential security issue.

References

Affected components

  • SAP NetWeaver 7.0 BI Java
  • SAP NetWeaver BI 7.01 (SAP NW BI7.0 EhP 1)
  • SAP NetWeaver BI 7.30 (SAP NW BI7.30)
  • SAP Business Objects Enterprise 4.0 (SAP BOE 4.0)

Full note on SAP: SAP Support Launchpad note 1542355

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More