Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to BI-BIP-ADM, SAP security note 2189178

SAP Note 2189178
SAP Security Note
Medium priority

SAP security note 2189178, “Potential Information Disclosure in BI-BIP-ADM”, is a program error note released on December 8, 2015. Below are the symptom and SAP recommended solution.

ComponentCMS / Auditing issues (excl. 3rd Party Authentication)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released onDecember 8, 2015

Description

Symptom

An attacker can discover information related to servers in BI-BIP-ADM using BI-BIP-SDK. This information includes database configurations, auditing status, port numbers, and server metrics, which can be leveraged to conduct more targeted attacks against BI-BIP.

Solution

The issue has been fixed in the following support package patches:

Reason and prerequisites

Information such as database configurations, auditing status, port numbers, and server metrics can be discovered using BI-BIP-SDK. This information may be utilized by an attacker to further target BI-BIP.

CVSS

Score 5.0 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2189178

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More