SAP Security Note
High priority
SAP security note 2018681, "Missing authentication check in BI-BIP (unauthorized File Repository write access)", was released on 19.02.2015. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An unauthenticated user can write arbitrary files to a BI Server.
Solution
Upgrade: install BI 4.1 SP04 or one of its subsequent patches or support packs.
Workaround for earlier patches: in earlier patches of BI 4.0 and BI 4.1, configure the File Repository Server to run in FIPS mode by adding -fips to its command line arguments, or enable Corba SSL. Refer to the Administration guide for more information.
Reason and prerequisites
BI-BIP File Repository Server can allow arbitrary file writes for unauthenticated users. The presence of such files can affect other applications within BI-BIP.
CVSS
Score 6.4 Vector: AV:N/AC:L/AU:N/C:N/I:P/A:P
Affected components
- BI-BIP-ADM (Business intelligence solutions > Business intelligence platform > BI Servers, security, Crystal Reports in Launchpad)
Full note on SAP: SAP Support Launchpad note 2018681
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
