Skip links

Critical Authentication Vulnerability in SAP BusinessObjects Business Intelligence Platform (CVE-2024-41730)

On August 13, 2024, SAP released a critical security patch addressing a severe authentication vulnerability in SAP BusinessObjects Business Intelligence Platform. This blog post aims to provide an overview of the vulnerability, its potential impact, and steps for mitigation.

Vulnerability Details

  • CVE ID: CVE-2024-41730
  • CVSS v3.0 Base Score: 9.8 (Critical)
  • Affected Component: SAP BusinessObjects Business Intelligence Platform
  • Vulnerability Type: Missing Authentication Check

Description

The vulnerability affects the Single Sign-On (SSO) functionality of the Enterprise authentication in SAP BusinessObjects Business Intelligence Platform. An unauthorized attacker can exploit this vulnerability to obtain a logon token using a REST endpoint, potentially leading to full system compromise.

Impact

If successfully exploited, this vulnerability can have severe consequences:

  • High impact on confidentiality: Unauthorized access to sensitive business intelligence data
  • High impact on integrity: Potential manipulation of BI reports and data
  • High impact on availability: Possible disruption of BI services

The critical CVSS score of 9.8 underscores the severity of this vulnerability and the urgent need for patching.

Affected Versions

  • ENTERPRISE 430
  • ENTERPRISE 440


PoC
[Details hidden – will be published after 3 months of the patch release]

Patch for CVE-2024-41730

Mitigation

SAP has released patches to address this vulnerability. The Single Sign-On Enterprise authentication is now secure by default after applying the patch.

Patch Information

Patches are available for the following versions:

  1. SBOP BI PLATFORM SERVERS 4.3 – Patch Level SP005
  2. SBOP BI PLATFORM SERVERS 2025 – Patch Level SP00
  3. SBOP BI PLATFORM SERVERS 4.3 – Patch Level SP004

It is strongly recommended that all affected organizations apply these patches as soon as possible.

Workaround

SAP has not provided any workaround for this vulnerability. The only mitigation is to apply the provided patches.

Recommendations

  1. Identify all instances of SAP BusinessObjects Business Intelligence Platform in your organization.
  2. Prioritize the application of the security patches based on the criticality of the affected systems.
  3. Conduct a thorough security assessment of your BI environment to identify any potential compromise.
  4. Review and enhance your authentication mechanisms and access controls.
  5. Monitor system logs for any suspicious activities, especially those related to authentication and token generation.

Conclusion

The discovery of CVE-2024-41730 highlights the ongoing importance of robust security measures in business intelligence platforms. Organizations using SAP BusinessObjects Business Intelligence Platform should treat this vulnerability with utmost urgency and apply the patches immediately to protect their critical business data and operations.

Stay vigilant and ensure your SAP environments are always up-to-date with the latest security patches.

Udemy SAP Security Course.

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series. This course will help you master SAP security fundamentals, from securing SAP environments to managing user access and addressing vulnerabilities. It is ideal for IT professionals and SAP administrators, providing practical skills to safeguard critical business assets. Whether you’re a beginner or an expert looking to deepen your SAP security knowledge, this course is perfect for you.

More to explorer

SAP Security Patch Day – September 2024

As the second Tuesday of September 2024 approaches, SAP administrators and security professionals are preparing for another crucial event: SAP Security Patch

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.