SAP security note 2751470, "[CVE-2019-0348] Encryption not enforced in SAP BusinessObjects Business Intelligence Platform (Web Intelligence)", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) can access the database with an unencrypted connection, even if the quality of protection should require encryption.
Solution
Encryption is now enforced when the CMS properties request encryption.
This issue is fixed in the patches listed in the "Support Packages & Patches" section below. The "Support Packages & Patches" section will be populated with the relevant patch levels once they are released.
For Business Intelligence Platform maintenance schedule and strategy, see the Knowledge Base Article 2144559 in the References section.
If the session to the platform is not valid, then DSL forbids all connections to SAP BW because the connection could be encrypted or not. A valid session is mandatory for a successful connection.
CVSS
Score 3.5 Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
References
- 2144559 – BI 4.x Maintenance Strategy & Schedule
- 2738796 – [CVE-2019-0289] Information Disclosure in SAP BusinessObjects Business Intelligence platform / Analysis for OLAP
Full note on SAP: SAP Support Launchpad note 2751470
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
