Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Port scanning via URL Reporting in SAP BusinessObjects Enterprise, SAP security note 2336795

SAP Note 2336795

SAP security note 2336795, "Port Scanning via URL Reporting in SAP BusinessObjects Enterprise". Below are the symptom and SAP recommended solution.

Description

Symptom

The View Report functionality of the CrystalReports module can be exploited to perform port and system scans on the internal network connected to the BusinessObjects system. An attacker can leverage this vulnerability to identify running services and gain insights into the operating system in use.

Impact:

  • Unauthorized port and system scanning of the internal network.
  • Potential exposure of network services and operating system details.

Solution

SAP has addressed this issue by making the response time random, mitigating the ability to perform effective scans.

Reason and prerequisites

Attacker has access to the URL reporting feature.

CVSS

Score 5.8 Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2336795

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More