SAP security note 2737278, "[CVE-2019-0287] Information Disclosure in SAP BusinessObjects Business Intelligence platform / Central Management Server". Below are the symptom and the SAP recommended solution.
Description
Symptom
Under certain conditions, SAP BusinessObjects Business Intelligence platform / Central Management Server allows an attacker to access information which would otherwise be restricted.
Some well-known impacts of Information Disclosure are:
- Loss of information and system configuration confidentiality: the list of user names and roles imported from SAP NetWeaver BI systems (BW) can be disclosed.
- Information gathering for further exploits and attacks.
Solution
The Central Management Server retains the SNC configuration during its lifetime.
This issue is fixed in the patches listed in the Support Packages & Patches section below.
For the Business Intelligence Platform maintenance schedule and strategy, see Knowledge Base Article 2144559 in the References section.
Reason and prerequisites
The issue impacts the users and roles synchronization between the Central Management Server and BW systems. It occurs when SAP authentication is configured using Secure Network Communications (SNC) in the Central Management Console. In some circumstances, the Central Management Server forgets the configuration, causing the communication to flow in clear text until the server restarts.
CVSS
Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
References
- 2144559 – BI 4.x Maintenance Strategy & Schedule
- 2738796 – [CVE-2019-0289] Information Disclosure in SAP BusinessObjects Business Intelligence platform / Analysis for OLAP
Full note on SAP: SAP Support Launchpad note 2737278
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
