SAP security note 2018682, "Potential information disclosure relating to BI-BIP (unauthorized File Repository read access)". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information relating to BI-BIP.
Solution
Install BI 4.1 SP04 or one of its subsequent patches or support packs. In earlier patches of BI 4.0 and BI 4.1, an equivalent workaround is configuring the File Repository Server to run in FIPS mode by adding -fips to its command line arguments.
Reason and prerequisites
Documents managed within a BI system, which could contain sensitive data, can be discovered using BI-BIP-SDK.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
Affected components
- ENTERPRISE: 4.0 to 4.0, 410 to 410
Full note on SAP: SAP Support Launchpad note 2018682
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
