SAP security note 2180555, "Potential Information Disclosure in BusinessObjects Semantic Layer SDK". Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information related to the BusinessObjects Semantic Layer SDK used in the SAP BusinessObjects Business Intelligence platform. This information could be utilized to specialize attacks against databases queried by customer reports.
Solution
The issue has been fixed in the patches listed in the “Support Package Patches” section. For the Business Intelligence Platform maintenance schedule and strategy, see Knowledge Base Article 2144559.
Reason and prerequisites
Information such as database structure can be discovered using the BusinessObjects Semantic Layer SDK. This information may be used by an attacker to target databases further and attempt SQL injection attacks. However, the risk is low because no information on how to establish connections to these databases is available.
CVSS
Score 4.0 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N
Full note on SAP: SAP Support Launchpad note 2180555
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
