SAP security note 2011396, “Missing authorization check in BI-BIP-ADM”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of BI-BIP-ADM to which access should be restricted. This may result in an escalation of privileges.
Solution
Install one of the following or one of their subsequent patches or support packs:
- BI 4.0 Patch 9.2
- BI 4.0 SP10
- BI 4.1 Patch 3.1
- BI 4.1 SP04
Reason and prerequisites
BI-BIP-ADM does not contain authorization checks for checking an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
CVSS
Score 6.4 Vector: AV:N/AC:L/AU:N/C:N/I:P/A:P
Affected components
- BO-WEBAPP: 4.0 – 4.0+
Full note on SAP: SAP Support Launchpad note 2011396
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



