SAP Security Note
Medium priority
SAP security note 2764513, "[CVE-2019-0333] Information Disclosure in SAP Business Objects Business Intelligence Platform (Web Intelligence and CMC)", is a program error note released on 13.08.2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This SAP security note addresses several vulnerabilities identified in SAP Business Objects. The vulnerability details along with their CVE relevant information can be found below.
Information Disclosure
CVE-2019-0333
CVSS Score: 6.5
Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
This issue could lead Web Intelligence to fail to respect data restrictions when refreshing documents with Prompts, allowing users to retrieve more data than their authorized security profile permits. Specifically, row-level security is not enforced, potentially disclosing information to unauthorized users.
CVE-2019-0346
CVSS Score: 5.3
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
An unencrypted communication error in the Central Management Console (CMC) leads to the disclosure of a list of usernames and roles imported from SAP Netweaver BI systems (BW). Under certain conditions, the Central Management Server allows an attacker to access information that would otherwise be restricted.
Impacts of Information Disclosure:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
- Row-Level Security Activation: Ensure that row-level security is correctly activated to maintain the integrity of Web Intelligence documents.
- Encryption of Parameters: Parameters are now correctly passed during connection to ensure encryption.
This issue is resolved in the patches listed in the "Support Packages & Patches" section below. For the Business Intelligence Platform maintenance schedule and strategy, refer to the Knowledge Base Article 2144559 in the References section.
Reason and prerequisites
Bypassing data filters is observed only with Web Intelligence documents containing at least one query with a defined Prompt.
CVSS
Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
References
Affected components
- ENTERPRISE 420
Full note on SAP: SAP Support Launchpad note 2764513
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
