Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential disclosure of persisted data in BW RFC, SAP security note 1581717

SAP Note 1581717

SAP security note 1581717, "Potential Disclosure of Persisted Data in BW RFC". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Security Note 1581717 addresses a critical SQL injection vulnerability in SAP NetWeaver BW RFCs. A malicious user can exploit this vulnerability using specially crafted inputs to modify database commands, potentially retrieving additional persisted data from the system.

Solution

To mitigate this vulnerability, apply the appropriate Support Package for your SAP NetWeaver BW version:

  • SAP NetWeaver BW 7.00: import Support Package 27 (SAPKW70027), available via SAP Note 1567706 titled "SAPBWNews NW BW 7.0 ABAP SP27".
  • SAP NetWeaver BW 7.01: import Support Package 10 (SAPKW70110), available via SAP Note 1419539 titled "SAPBINews NW7.01 BW ABAP SP10".
  • SAP NetWeaver BW 7.02: import Support Package 09 (SAPKW70209), available via SAP Note 1581161 titled "Preliminary Version SAPBWNews NW BW 7.02 ABAP SP09".
  • SAP NetWeaver BW 7.11: import Support Package 08 (SAPKW71108), available via SAP Note 1510977 titled "Preliminary Version SAPBINews NW7.11 BW ABAP SP8".
  • SAP NetWeaver BW 7.30: import Support Package 03 (SAPKW73003), available via SAP Note 1538941 titled "SAPBWNews NW7.30 BW ABAP SP03".

You can also use the correction instructions provided in the note. Before applying the Support Package, ensure you check SAP Note 875986 for transaction SNOTE.

References

Affected components

  • SAP NetWeaver BW 7.00
  • SAP NetWeaver BW 7.01 (Enhancement Package 1)
  • SAP NetWeaver BW 7.02 (Enhancement Package 2)
  • SAP NetWeaver BW 7.11
  • SAP NetWeaver BW 7.30

Full note on SAP: SAP Support Launchpad note 1581717

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More