Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0348 Encryption not enforced in SAP BusinessObjects Business Intelligence Platform (Web Intelligence), SAP security note 2751470

SAP Note 2751470

SAP security note 2751470, "[CVE-2019-0348] Encryption not enforced in SAP BusinessObjects Business Intelligence Platform (Web Intelligence)", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) can access the database with an unencrypted connection, even if the quality of protection should require encryption.

Solution

Encryption is now enforced when the CMS properties request encryption.

This issue is fixed in the patches listed in the "Support Packages & Patches" section below. The "Support Packages & Patches" section will be populated with the relevant patch levels once they are released.

For Business Intelligence Platform maintenance schedule and strategy, see the Knowledge Base Article 2144559 in the References section.

If the session to the platform is not valid, then DSL forbids all connections to SAP BW because the connection could be encrypted or not. A valid session is mandatory for a successful connection.

CVSS

Score 3.5 Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N

References

Full note on SAP: SAP Support Launchpad note 2751470

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More