Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2447 SQL Injection vulnerability in BI Launchpad Web Intelligence, SAP security note 2644154

SAP Note 2644154
High priority

SAP security note 2644154, "[CVE-2018-2447] SQL Injection Vulnerability in BI Launchpad Web Intelligence", is a program error note released on 14.08.2018. Below are the symptom, SAP recommended solution and the affected software components.

CategoryProgram error
PriorityHigh priority
StatusReleased for Customer
Released on14.08.2018

Description

Symptom

BI Launchpad Web Intelligence allows an attacker to execute crafted InfoObject queries, exposing the CMS InfoObjects database.

Solution

SAP has validated the query string before its use in query statements of the related files to mitigate this vulnerability.

CVSS

Score 7.7 Vector: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

References

Affected components

  • ENTERPRISE 420 to 420

Full note on SAP: SAP Support Launchpad note 2644154

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More