SAP security note 2196420, “Potential information disclosure relating to BW-BEX-ET-WB-7X”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker might gain access to sensitive data for which he/she is not authorized.
Solution
- SAP NetWeaver 7.0 BW Front End for GUI 730: Import Front-End Patch (FEP) 920 (or higher) for SAP NetWeaver 7.x BW Front End (bi730sp9_920-10004472.exe) into your system. The FEP will be available as soon as SAP Note 1885328 with the short text “SAPBWNews NW 7.x BW Add-On Frontend Patch 920 – GUI 7.30”, which describes this FEP in more detail, is released for customers. This SAP Note might already be available before the FEP is released. You can check the planned availability dates in the attached SAP Note 1085218.
- SAP NetWeaver 7.0 BW Front End for GUI 740: Import Front-End Patch (FEP) 400 (or higher) for SAP NetWeaver 7.x BW Front End (bi740sp4_400-10004472.exe) into your system. The FEP will be available as soon as SAP Note 2083607 with the short text “SAPBWNews NW 7.x BW Add-On Frontend Patch 400 – GUI 7.40”, which describes this FEP in more detail, is released for customers. This SAP Note might already be available before the FEP is released. You can check the planned availability dates in the attached SAP Note 1085218.
Reason and prerequisites
Unauthorized access to sensitive data.
References
Referenced by
- 1885328: SAPBWNews NW 7.x BW Add-On Frontend Patch 920 – GUI 7.30
Affected components
- BIADDON (730 to 730)
- BIADDON (740 to 740)
Full note on SAP: SAP Support Launchpad note 2196420
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
