SAP security note 1966056, "Code injection vulnerability in BW". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
BW contains code that permits the execution of arbitrary program code of the user’s choice. An attacker can control the system’s behavior or potentially escalate privileges by executing malicious code without having their own legitimate credentials.
Solution
To address this vulnerability, apply the appropriate Support Package for your SAP NetWeaver BW version:
- SAP NetWeaver BW 7.00: Support Package SAPKW70033, SAP Note 1930762 “SAPBWNews NW BW 7.0 ABAP SP33”.
- SAP NetWeaver BW 7.01 (SAP NW BW7.0 EHP 1): Support Package SAPKW70116, SAP Note 1936601 “SAPBINews NW7.01 BW ABAP SP16”.
- SAP NetWeaver BW 7.02 (SAP NW BW7.0 EHP 2): Support Package SAPKW70216, SAP Note 1940530 “Preliminary Version SAPBWNews NW BW 7.02 ABAP SP16”.
- SAP NetWeaver BW 7.11: Support Package SAPKW71114, SAP Note 1940531 “Preliminary Version SAPBINews NW7.11 BW ABAP SP14”.
You can also use the correction instructions provided in this note to implement the fixes before the corresponding Support Packages are available. Ensure you check SAP Note 1668882 for transaction SNOTE before applying the correction instructions.
Reason and prerequisites
The program code allows the definition and execution of user-defined code that alters the system’s behavior. A valid and authenticated user is required.
Depending on the code, the user can:
- Inject and run their own code
- Obtain additional information that should not be displayed
- Modify or delete data
- Modify the system’s output
- Create new users with higher privileges
- Perform a denial of service attack
Affected components
- SAP_BW: 700 to 702, 710 to 720
- SAP_BW_VIRTUAL_COMP: 701
Full note on SAP: SAP Support Launchpad note 1966056
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



