SAP security note 2701027, "[CVE-2019-0398] Cross-Site Request Forgery (CSRF) vulnerability in SAP BusinessObjects Business Intelligence Platform (Monitoring application)". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The BOE Monitoring Application allows an attacker to trick an authenticated user into sending unintended requests to the web server. This vulnerability is due to insufficient CSRF protection.
Potential impacts include actions on behalf of authenticated users, where attackers can perform actions without the user’s consent, and loss of non-repudiation, where users may be unable to deny actions performed via the vulnerability.
Solution
The XSRF protection framework is now properly utilized, ensuring correct authentication tokens are present. This issue is fixed in the relevant support packages for the affected releases.
CVSS
Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
References
Affected components
- BUSINESS INTELLIGENCE PLATFORM MONITORING (BI-BIP-MON): Versions 4.1, 4.2, 4.3
Full note on SAP: SAP Support Launchpad note 2701027
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
