Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code injection vulnerability in BW-BEX-OT-OLAP, SAP security note 1786822

SAP Note 1786822

SAP security note 1786822, "Code injection vulnerability in BW-BEX-OT-OLAP," is a note covering the symptom, SAP recommended solution and the reason and prerequisites.

Description

Symptom

BW-BEX-OT-OLAP contains code that permits the execution of arbitrary program code of the user’s choice. An attacker can control the system’s behavior or potentially escalate privileges by executing malicious code without having their own legitimate credentials.

Solution

Apply the appropriate Support Package for your SAP NetWeaver BW version:

  • SAP NetWeaver BW 7.00: Import Support Package 31 (SAPKW70031) after SAP Note 1782745.
  • SAP NetWeaver BW 7.01 (EHP 1): Import Support Package 13 (SAPKW70113) after SAP Note 1732064.
  • SAP NetWeaver BW 7.02 (EHP 2): Import Support Package 13 (SAPKW70213) after SAP Note 1741512.
  • SAP NetWeaver BW 7.11: Import Support Package 11 (SAPKW71107) after SAP Note 1734666.
  • SAP NetWeaver BW 7.30: Import Support Package 9 (SAPKW73009) after SAP Note 1750249.
  • SAP NetWeaver BW 7.31: Import Support Package 7 (SAPKW73107) after SAP Note 1782744.

You can also use the correction instructions to apply the security note immediately. Before doing so, ensure you review SAP Note 875986 for transaction SNOTE. This SAP Note might be available before the Support Package release, though it may still be labeled as a “preliminary version.”

Reason and prerequisites

The program code allows defining and executing user-defined code that alters system behavior. A valid and authenticated user is required with authorization to transaction RSRV to define the code and edit/change authorization for debugging. Depending on the code, the user can:

  • Inject and run their own code
  • Obtain additional information that should not be displayed
  • Modify or delete data
  • Modify system output
  • Create new users with higher privileges
  • Perform a denial of service attack

CVSS

Score 4.0 Vector: AV:N/AC:L/AU:S/C:P/I:N/A:N

References

Full note on SAP: SAP Support Launchpad note 1786822

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More