High priority
SAP security note 1956096, "Missing whitelist check in BW-WHM-DBA", is a note released on 26.02.2014. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of BW-WHM-DBA to which access should be restricted. This may result in an escalation of privileges.
Solution
To resolve this issue, please apply the appropriate Support Package as mentioned below:
- SAP NetWeaver BW 7.30: import Support Package 11 for SAP NetWeaver BW 7.30 (SAPKW73011) into your BW system. This Support Package will be available once SAP Note 1878293 with the short text "SAPBWNews NW7.30 BW ABAP SP11" is released for customers.
- SAP NetWeaver BW 7.31 (SAP NW BW 7.3 EnhP 1): import Support Package 11 for SAP NetWeaver BW 7.31 (SAPKW73111) into your BW system. This Support Package will be available once SAP Note 1914639 with the short text "SAPBWNews NW BW 7.31/7.03 ABAP SP11" is released for customers.
- SAP NetWeaver BW 7.40: import Support Package 6 for SAP NetWeaver BW 7.40 (SAPKW74006) into your BW system. This Support Package will be available once SAP Note 1920525 with the short text "SAPBWNews NW BW 7.4 ABAP SP06" is released for customers.
In urgent cases, you can use the correction instructions provided. Before using the correction instructions, ensure you check SAP Note 1668882 for transaction SNOTE. This SAP Note might already be available before the Support Package is released; however, the short text will still contain the term "preliminary version."
Reason and prerequisites
BW-WHM-DBA does not contain required checks against a positive set of allowed functions (i.e., whitelist) during the execution of these functions. This is required to verify that authenticated users are allowed to access these functions. The missing check may result in undesired system behavior.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
References
Full note on SAP: SAP Support Launchpad note 1956096
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



