SAP security note 2561202, "Command Injection through Web Intelligence Report or DataProvider export", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
Users can insert unsafe Excel commands via Web Intelligence Data or Formula into a Report that will be executed by Excel when importing the exported CSV data from a Web Intelligence Report.
Solution
This issue is fixed in the patches listed in the "Support Packages & Patches" section below. The "Support Packages & Patches" section will be populated with the relevant patch levels once they are released.
For the Business Intelligence Platform maintenance schedule and strategy, see Knowledge Base Article 2144559.
Reason and prerequisites
This fix is required because Web Intelligence outputs are supposed to be trusted. The CSV output is now escaped to disable the Excel capability of transforming string data into commands when Excel reads some special characters.
Before the attacks can be performed, Excel users must manually accept running these commands.
CVSS
Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
References
- BI 4.x Maintenance Strategy & Schedule (2144559)
- SAP Note 2708439: ‘-‘ characters gets replaced by ‘ -‘ in the csv file when exporting a report in Web Intelligence
Full note on SAP: SAP Support Launchpad note 2561202
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
