Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0398 Cross-Site Request Forgery (CSRF) vulnerability in SAP BusinessObjects Business Intelligence Platform (Monitoring application), SAP security note 2701027

SAP Note 2701027

SAP security note 2701027, "[CVE-2019-0398] Cross-Site Request Forgery (CSRF) vulnerability in SAP BusinessObjects Business Intelligence Platform (Monitoring application)". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The BOE Monitoring Application allows an attacker to trick an authenticated user into sending unintended requests to the web server. This vulnerability is due to insufficient CSRF protection.

Potential impacts include actions on behalf of authenticated users, where attackers can perform actions without the user’s consent, and loss of non-repudiation, where users may be unable to deny actions performed via the vulnerability.

Solution

The XSRF protection framework is now properly utilized, ensuring correct authentication tokens are present. This issue is fixed in the relevant support packages for the affected releases.

CVSS

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

References

Affected components

  • BUSINESS INTELLIGENCE PLATFORM MONITORING (BI-BIP-MON): Versions 4.1, 4.2, 4.3

Full note on SAP: SAP Support Launchpad note 2701027

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More