Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure in BPC or SSM Server, SAP security note 1654303

SAP Note 1654303

SAP security note 1654303, "Potential information disclosure in BPC or SSM Server", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

An attacker can discover information related to SAP BusinessObjects Planning and Consolidation 10.0 (version for the NetWeaver platform) and SAP Strategy Management Application Component 10.0 using the SBC Business User Interface, Reporting component. This information can be leveraged to tailor attacks against SAP BusinessObjects Planning and Consolidation and SAP Strategy Management Application Reporting component.

Solution

Apply the following Service Packs or higher:

  • SAP STRATEGY MANAGEMENT APPLICATION COMPONENT 10.0 – Service Pack SP001, released on 10.08.2011
  • SAP BusinessObjects Planning and Consolidation 10.0, version for the NetWeaver platform – Service Pack SP004, released on 14.10.2011

Reason and prerequisites

Information such as the contents of report data exchanged with the application server used for reporting can be discovered using SBC BUI Reporting. An attacker may use this information to further target BPC or SSM.

Full note on SAP: SAP Support Launchpad note 1654303

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More