SAP security note 2018683, “Potential information disclosure relating to BI-BIP”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information relating to BI-BIP-ADM. This information could be used to allow the attacker to specialize their attacks against BI-BIP.
Solution
Install one of the following or one of their subsequent patches or support packs:
- XI 3.1 SP6 FP6
- XI 3.1 SP7 FP3
- BI 4.0 Patch 9.4
- BI 4.0 SP10
- BI 4.1 Patch 3.2
- BI 4.1 Patch 4.1
- BI 4.1 SP05
Reason and prerequisites
Information such as server versions, host addresses, server names, and listening ports can be discovered using BI-BIP-SDK. This information may be used by an attacker to further target BI-BIP.
CVSS
Score 5.0 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
Affected components
- BO-WEBAPP: 4.0+
- ENTERPRISE XI 3.1
- ENTERPRISE 410
Full note on SAP: SAP Support Launchpad note 2018683
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




