Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0333 Information Disclosure in SAP Business Objects Business Intelligence Platform (Web Intelligence and CMC), SAP security note 2764513

SAP Note 2764513
SAP Security Note
Medium priority

SAP security note 2764513, "[CVE-2019-0333] Information Disclosure in SAP Business Objects Business Intelligence Platform (Web Intelligence and CMC)", is a program error note released on 13.08.2019. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBusiness intelligence solutions > Reporting, analysis, and dashboards > Web Intelligence > Back End/Server > Data Provider
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version10
StatusReleased for Customer
Released on13.08.2019
LanguageEnglish

Description

Symptom

This SAP security note addresses several vulnerabilities identified in SAP Business Objects. The vulnerability details along with their CVE relevant information can be found below.

Information Disclosure

CVE-2019-0333
CVSS Score: 6.5
Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
This issue could lead Web Intelligence to fail to respect data restrictions when refreshing documents with Prompts, allowing users to retrieve more data than their authorized security profile permits. Specifically, row-level security is not enforced, potentially disclosing information to unauthorized users.

CVE-2019-0346
CVSS Score: 5.3
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
An unencrypted communication error in the Central Management Console (CMC) leads to the disclosure of a list of usernames and roles imported from SAP Netweaver BI systems (BW). Under certain conditions, the Central Management Server allows an attacker to access information that would otherwise be restricted.

Impacts of Information Disclosure:

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

  • Row-Level Security Activation: Ensure that row-level security is correctly activated to maintain the integrity of Web Intelligence documents.
  • Encryption of Parameters: Parameters are now correctly passed during connection to ensure encryption.

This issue is resolved in the patches listed in the "Support Packages & Patches" section below. For the Business Intelligence Platform maintenance schedule and strategy, refer to the Knowledge Base Article 2144559 in the References section.

Reason and prerequisites

Bypassing data filters is observed only with Web Intelligence documents containing at least one query with a defined Prompt.

CVSS

Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

References

Affected components

  • ENTERPRISE 420

Full note on SAP: SAP Support Launchpad note 2764513

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More