SAP security note 2733972, "Cross-Site Request Forgery (CSRF) vulnerability in BICS InA Interface". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
BICS InA Interface allows an attacker to trick an authenticated user into sending unintended requests to the web server. This vulnerability is due to insufficient CSRF protection.
Impacts:
- Attacker could take actions on behalf of an authenticated user
- Loss of non-repudiation
Solution
To mitigate this vulnerability, apply the appropriate Support Package for your SAP BW system version as listed below:
- SAP BW 7.40: Support Package 22 (SAPKW74022)
- SAP BW 7.50: Support Package 15 (SAPK-75015INSAPBW)
- SAP BW 7.51: Support Package 8 (SAPK-75108INSAPBW)
- SAP BW 7.52: Support Package 4 (SAPK-75204INSAPBW)
- SAP BW 7.53: Support Package 2 (SAPK-75302INSAPBW)
- SAP BW/4HANA 1.0: Support Package 12 (SAPK-10012INDW4CORE)
Alternatively, you can use the correction instructions provided in this SAP Note. Before applying the correction instructions, ensure you review SAP Note 1668882 and SAP Note 2248091 for transaction SNOTE.
CVSS
Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Affected components
- BW-BEX-OT-BICS-INA
Full note on SAP: SAP Support Launchpad note 2733972
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




