SAP Security Note
SAP security note 2742468, "CVE-2019-0331, CVE-2019-0332, CVE-2019-0335: Multiple Vulnerabilities in SAP BusinessObjects BI Platform", is a program error note released on August 13, 2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP has released Security Note 2742468 addressing multiple vulnerabilities in the SAP BusinessObjects Business Intelligence Platform, specifically affecting BI Workspace, Infoview, and the Central Management Console (CMC).
CVE-2019-0331: Information Disclosure
Under certain conditions, BI Workspace allows an attacker to access restricted information. CVSS Score: 5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
CVE-2019-0332: Stored Cross-Site Scripting (XSS)
An attacker can inject malicious scripts via the search keyword, which are executed during the search operation. CVSS Score: 4.8 (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N)
CVE-2019-0335: Stored Cross-Site Scripting (XSS)
A malicious payload can be stored in the description field of a user account, triggering upon mouse interaction. CVSS Score: 4.8 (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N)
Impact:
- Information Disclosure: Unauthorized access to sensitive information and system configurations.
- Cross-Site Scripting (XSS): Execution of malicious scripts leading to potential data theft and session hijacking.
Solution
- Information Disclosure: Removal of unused code that led to the vulnerability.
- XSS: Proper encoding of parameters to prevent script injection.
References
Affected components
- Central Management Console (CMC) (BI-BIP-CMC)
- BI Workspaces (Dashboard Builder) (BI-BIP-BIW)
Full note on SAP: SAP Support Launchpad note 2742468
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
