SAP security note 2638288, "Information Disclosure in OLAP Queries", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
Under certain conditions OLAP queries allow an attacker to access information which would otherwise be restricted.
Some well-known impacts of Information Disclosure are:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
Implement the appropriate Support Package for your SAP BW version as soon as the corresponding SAP Note is released:
- SAP BW 7.40: implement Support Package 21 (SAPKW74021).
- SAP BW 7.50: implement Support Package 13 (SAPK-75013INSAPBW).
- SAP BW 7.51: implement Support Package 7 (SAPK-75107INSAPBW).
- SAP BW 7.52: implement Support Package 3 (SAPK-75203INSAPBW).
- SAP BW 7.53: implement Support Package 1 (SAPK-75301INSAPBW).
- SAP BW/4HANA 1.0: implement Support Package 10 (SAPK-10010INDW4CORE).
Before applying the correction instructions, ensure you review SAP Note 1668882 and SAP Note 2248091 using transaction SNOTE.
Reason and prerequisites
Program error.
Full note on SAP: SAP Support Launchpad note 2638288
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
