Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site AJAX Requests vulnerability in SAP BusinessObjects, SAP security note 2381071

SAP Note 2381071
SAP Security Note
High priority

SAP security note 2381071, "Cross-Site AJAX Requests Vulnerability in SAP BusinessObjects", is a program error note released on August 8, 2017. Below are the symptom and SAP recommended solution.

ComponentBusiness intelligence solutions > Business intelligence platform > BI Workspaces (Dashboard Builder)
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version9
StatusReleased for Customer
Released onAugust 8, 2017
LanguageEnglish

Description

Symptom

An outdated version of the Prototype JS library was being used within BusinessObjects, allowing attackers to make "cross-site AJAX requests" via unknown vectors.

Solution

This issue is fixed in the patches listed in the "Support Package Patches" section below. To apply the fix, download and install the relevant support packages for your system.

For more details on the maintenance schedule and strategy, refer to Knowledge Base Article 2144559.

CVSS

Score 7.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

References

Full note on SAP: SAP Support Launchpad note 2381071

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More