Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to BI-BIP, SAP security note 2018683

SAP Note 2018683

SAP security note 2018683, “Potential information disclosure relating to BI-BIP”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An attacker can discover information relating to BI-BIP-ADM. This information could be used to allow the attacker to specialize their attacks against BI-BIP.

Solution

Install one of the following or one of their subsequent patches or support packs:

  • XI 3.1 SP6 FP6
  • XI 3.1 SP7 FP3
  • BI 4.0 Patch 9.4
  • BI 4.0 SP10
  • BI 4.1 Patch 3.2
  • BI 4.1 Patch 4.1
  • BI 4.1 SP05

Reason and prerequisites

Information such as server versions, host addresses, server names, and listening ports can be discovered using BI-BIP-SDK. This information may be used by an attacker to further target BI-BIP.

CVSS

Score 5.0 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected components

  • BO-WEBAPP: 4.0+
  • ENTERPRISE XI 3.1
  • ENTERPRISE 410

Full note on SAP: SAP Support Launchpad note 2018683

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More