Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to BusinessObjects Semantic Layer SDK, SAP security note 2180555

SAP Note 2180555

SAP security note 2180555, "Potential Information Disclosure in BusinessObjects Semantic Layer SDK". Below are the symptom and SAP recommended solution.

Description

Symptom

An attacker can discover information related to the BusinessObjects Semantic Layer SDK used in the SAP BusinessObjects Business Intelligence platform. This information could be utilized to specialize attacks against databases queried by customer reports.

Solution

The issue has been fixed in the patches listed in the “Support Package Patches” section. For the Business Intelligence Platform maintenance schedule and strategy, see Knowledge Base Article 2144559.

Reason and prerequisites

Information such as database structure can be discovered using the BusinessObjects Semantic Layer SDK. This information may be used by an attacker to target databases further and attempt SQL injection attacks. However, the risk is low because no information on how to establish connections to these databases is available.

CVSS

Score 4.0 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2180555

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More