Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing whitelist check in BW-WHM-DBA, SAP security note 1956096

SAP Note 1956096
High priority

SAP security note 1956096, "Missing whitelist check in BW-WHM-DBA", is a note released on 26.02.2014. Below are the symptom, SAP recommended solution and the affected software components.

ComponentSAP Business Warehouse > Data Warehouse Management > Data Basis (BW-WHM-DBA)
PriorityCorrection with high priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on26.02.2014
LanguageEnglish

Description

Symptom

An authenticated user can use functions of BW-WHM-DBA to which access should be restricted. This may result in an escalation of privileges.

Solution

To resolve this issue, please apply the appropriate Support Package as mentioned below:

  • SAP NetWeaver BW 7.30: import Support Package 11 for SAP NetWeaver BW 7.30 (SAPKW73011) into your BW system. This Support Package will be available once SAP Note 1878293 with the short text "SAPBWNews NW7.30 BW ABAP SP11" is released for customers.
  • SAP NetWeaver BW 7.31 (SAP NW BW 7.3 EnhP 1): import Support Package 11 for SAP NetWeaver BW 7.31 (SAPKW73111) into your BW system. This Support Package will be available once SAP Note 1914639 with the short text "SAPBWNews NW BW 7.31/7.03 ABAP SP11" is released for customers.
  • SAP NetWeaver BW 7.40: import Support Package 6 for SAP NetWeaver BW 7.40 (SAPKW74006) into your BW system. This Support Package will be available once SAP Note 1920525 with the short text "SAPBWNews NW BW 7.4 ABAP SP06" is released for customers.

In urgent cases, you can use the correction instructions provided. Before using the correction instructions, ensure you check SAP Note 1668882 for transaction SNOTE. This SAP Note might already be available before the Support Package is released; however, the short text will still contain the term "preliminary version."

Reason and prerequisites

BW-WHM-DBA does not contain required checks against a positive set of allowed functions (i.e., whitelist) during the execution of these functions. This is required to verify that authenticated users are allowed to access these functions. The missing check may result in undesired system behavior.

CVSS

Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P

References

Full note on SAP: SAP Support Launchpad note 1956096

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More