Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SQL Injection vulnerability in SAP Business Intelligence platform, SAP security note 2361633

SAP Note 2361633

SAP security note 2361633, “SQL Injection vulnerability in SAP Business Intelligence platform”. Below are the symptom and SAP recommended solution.

Description

Symptom

SAP BusinessObjects Business Intelligence platform 4.1 and 4.2 allows an attacker to execute crafted database queries, exposing the backend database.

  • Read sensitive data, modify or delete data from the database
  • Execute admin level operations on the database

Solution

Prompt answers are checked and attempts of SQL Injection raise invalid response errors.

This issue is fixed in the patches listed in the “Support Packages & Patches” section below. The “Support Packages & Patches” section will be populated with the relevant patch levels once they are released. For Business Intelligence Platform maintenance schedule and strategy, see the Knowledge Base Article 2144559 in the References section.

Reason and prerequisites

Environment: SAP BusinessObjects Business Intelligence platform 4.1 and 4.2

Cause: Prompting in Semantic Layer are not checked correctly. It is possible to build and add SQL statements in addition to the standard prompt answers.

CVSS

Score 6.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Full note on SAP: SAP Support Launchpad note 2361633

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More