SAP security note 2197262, "Information Disclosure in BI Reporting and Planning". Below are the symptom, SAP recommended solution, reason and prerequisites, the CVSS score, and references.
Description
Symptom
An attacker can discover information relating to the software version that is used in BW-PLA-IP-PMD. This information could be used to allow the attacker to specialize any further attacks against the planning modeller.
Solution
To resolve the issue, apply the Support Package or patch as mentioned below. Due to synchronized patch delivery, no updates for other components on both ABAP and Java sides are required.
- SAP NetWeaver 7.0 BI Java: Deploy Support Package 33 or Patch SP33 #20 (Support Package 33, Patch level 20) for SAP NetWeaver 7.0 BI Java.
- SAP NetWeaver BI 7.01 (SAP NW BI 7.0 EhP1): Deploy Support Package 18 or Patch SP18 #20 (Support Package 18, Patch level 20) for SAP NW BI7.0 EhP1 BI JAVA.
- SAP NetWeaver BI 7.02 (SAP NW BI 7.0 EhP2): Refer to Note 1589637 for the corresponding patch.
- SAP NetWeaver BI 7.30 to 7.50: Import the appropriate BI Java Patch for your specific version as detailed in Note 2292504 and refer to Note 1512355 for the delivery schedule.
For all other software component versions and support packages, refer to the Delivery Information section of the SAP Note.
Reason and prerequisites
Direct access to information about the used software version is possible.
CVSS
Score 5.3 / 10 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
References
Full note on SAP: SAP Support Launchpad note 2197262
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
