SAP security note 2039905, "Missing authorization check in BI-BIP-SCH", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can utilize functions of BI-BIP-SCH that should be restricted, potentially leading to an escalation of privileges.
This vulnerability allows unauthorized access to certain functionalities within BI-BIP-SCH, which may result in unintended system behavior and privilege escalation.
Solution
The issue has been addressed in the following SAP BusinessObjects Enterprise releases. Apply the specified Support Package (SP) patches to mitigate the vulnerability:
- SAP BusinessObjects Enterprise 4.0:
- SAP BusinessObjects Enterprise 4.1:
After applying the patches, restart the APS server hosting the search service and allow a few minutes for the fix to take effect.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
Full note on SAP: SAP Support Launchpad note 2039905
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
