High priority
SAP security note 2644154, "[CVE-2018-2447] SQL Injection Vulnerability in BI Launchpad Web Intelligence", is a program error note released on 14.08.2018. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
BI Launchpad Web Intelligence allows an attacker to execute crafted InfoObject queries, exposing the CMS InfoObjects database.
Solution
SAP has validated the query string before its use in query statements of the related files to mitigate this vulnerability.
CVSS
Score 7.7 Vector: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
References
Affected components
- ENTERPRISE 420 to 420
Full note on SAP: SAP Support Launchpad note 2644154
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



