Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to BI-BIP (unauthorized File Repository read access), SAP security note 2018682

SAP Note 2018682

SAP security note 2018682, "Potential information disclosure relating to BI-BIP (unauthorized File Repository read access)". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An attacker can discover information relating to BI-BIP.

Solution

Install BI 4.1 SP04 or one of its subsequent patches or support packs. In earlier patches of BI 4.0 and BI 4.1, an equivalent workaround is configuring the File Repository Server to run in FIPS mode by adding -fips to its command line arguments.

Reason and prerequisites

Documents managed within a BI system, which could contain sensitive data, can be discovered using BI-BIP-SDK.

CVSS

Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N

Affected components

  • ENTERPRISE: 4.0 to 4.0, 410 to 410

Full note on SAP: SAP Support Launchpad note 2018682

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More