HotNews
SAP security note 1567882, "Missing authorization check in BW RFC", is released on 19.07.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of BW to which access should be restricted. This may result in an escalation of privileges.
Solution
To address this issue, import the appropriate Support Package into your BW system:
- SAP NetWeaver BW 7.00: import Support Package 27 (SAPKW70027)
- SAP NetWeaver BW 7.01 (SAP NW BW 7.0 EnhP 1): import Support Package 09 (SAPKW70109)
- SAP NetWeaver BW 7.02 (SAP NW BW 7.0 EnhP 2): import Support Package 08 (SAPKW70208)
- SAP NetWeaver BW 7.11: import Support Package 07 (SAPKW71107)
- SAP NetWeaver BW 7.30: import Support Package 03 (SAPKW73003)
Reason and prerequisites
BW RFC does not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This may result in undesired system behavior.
CVSS
Score 8.2 Vector: AV:N/AC:M/AU:S/C:C/I:C/A:P
Full note on SAP: SAP Support Launchpad note 1567882
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
