SAP security note 1654303, "Potential information disclosure in BPC or SSM Server", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information related to SAP BusinessObjects Planning and Consolidation 10.0 (version for the NetWeaver platform) and SAP Strategy Management Application Component 10.0 using the SBC Business User Interface, Reporting component. This information can be leveraged to tailor attacks against SAP BusinessObjects Planning and Consolidation and SAP Strategy Management Application Reporting component.
Solution
Apply the following Service Packs or higher:
- SAP STRATEGY MANAGEMENT APPLICATION COMPONENT 10.0 – Service Pack SP001, released on 10.08.2011
- SAP BusinessObjects Planning and Consolidation 10.0, version for the NetWeaver platform – Service Pack SP004, released on 14.10.2011
Reason and prerequisites
Information such as the contents of report data exchanged with the application server used for reporting can be discovered using SBC BUI Reporting. An attacker may use this information to further target BPC or SSM.
Full note on SAP: SAP Support Launchpad note 1654303
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
