SAP security note 1885371, "Code injection vulnerability in BW-BEX-OT", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP has released Security Note 1885371 addressing a critical code injection vulnerability in BW-BEX-OT. This vulnerability allows an attacker to execute arbitrary program code, potentially controlling system behavior or escalating privileges without having legitimate credentials.
Exploiting this vulnerability, an attacker can:
- Inject and execute malicious code.
- Obtain unauthorized access to sensitive information.
- Modify or delete data.
- Create new users with elevated privileges.
- Perform denial of service (DoS) attacks.
Solution
Apply the appropriate Support Package for your SAP NetWeaver BW version:
- SAP NetWeaver BW 7.00: SAPKW70032
- SAP NetWeaver BW 7.01 (EHP 1): SAPKW70115
- SAP NetWeaver BW 7.02 (EHP 2): SAPKW70215
- SAP NetWeaver BW 7.11: SAPKW71113
- SAP NetWeaver BW 7.30: SAPKW73011
- SAP NetWeaver BW 7.31: SAPKW73110
- SAP NetWeaver BW 7.40: SAPKW74005
For urgent cases, refer to the Correction Instructions provided in the SAP Note. Ensure you review SAP Note 1668882 before applying corrections using transaction SNOTE.
CVSS
Score 4.6 Vector: AV:N/AC:H/AU:S/C:P/I:P/A:P
Affected components
- SAP NetWeaver BW 7.00 to 7.40
- SAP_BW
- SAP_BW_VIRTUAL_COMP
Full note on SAP: SAP Support Launchpad note 1885371
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



