SAP security note 1836717, “Hard-coded profiles in BW-BEX-ET”. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can authenticate to BW-BEX-ET without legitimate credentials or escalate privileges.
Solution
Apply the appropriate Support Package for your SAP NetWeaver BW version:
- SAP NetWeaver BW 7.00: Import Support Package 31 (SAPKW70031). Refer to SAP Note 1782745 for more details.
- SAP NetWeaver BW 7.01 (EHP 1): Import Support Package 14 (SAPKW70114). Refer to SAP Note 1794836 for more details.
- SAP NetWeaver BW 7.02 (EHP 2): Import Support Package 14 (SAPKW70214). Refer to SAP Note 1800952 for more details.
- SAP NetWeaver BW 7.11: Import Support Package 12 (SAPKW71112). Refer to SAP Note 1797080 for more details.
- SAP NetWeaver BW 7.30: Import Support Package 10 (SAPKW73010). Refer to SAP Note 1810084 for more details.
- SAP NetWeaver BW 7.31 (EHP 3): Import Support Package 8 (SAPKW73108). Refer to SAP Note 1813987 for more details.
- SAP NetWeaver BW 7.40: Import Support Package 3 (SAPKW74003). Refer to SAP Note 1818593 for more details.
Before applying correction instructions, ensure you review SAP Note 875986 for transaction SNOTE.
Reason and prerequisites
This vulnerability is caused by a hard-coded profile in the program’s source code. An attacker who specifies these credentials can log into the system without having been assigned legitimate access by the system administrator(s). Additionally, if a user already has privileges to log on, an escalation of privileges may be possible if the hard-coded account has higher access rights than the original user.
CVSS
Score 6.5 Vector: AV:N/AC:L/AU:S/C:P/I:P/A:P
Full note on SAP: SAP Support Launchpad note 1836717
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
