Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Hard-coded profiles in BW-BEX-ET, SAP security note 1836717

SAP Note 1836717

SAP security note 1836717, “Hard-coded profiles in BW-BEX-ET”. Below are the symptom and SAP recommended solution.

Description

Symptom

An attacker can authenticate to BW-BEX-ET without legitimate credentials or escalate privileges.

Solution

Apply the appropriate Support Package for your SAP NetWeaver BW version:

Before applying correction instructions, ensure you review SAP Note 875986 for transaction SNOTE.

Reason and prerequisites

This vulnerability is caused by a hard-coded profile in the program’s source code. An attacker who specifies these credentials can log into the system without having been assigned legitimate access by the system administrator(s). Additionally, if a user already has privileges to log on, an escalation of privileges may be possible if the hard-coded account has higher access rights than the original user.

CVSS

Score 6.5 Vector: AV:N/AC:L/AU:S/C:P/I:P/A:P

Full note on SAP: SAP Support Launchpad note 1836717

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More