Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to BW-BEX-ET-WB-7X, SAP security note 2196420

SAP Note 2196420

SAP security note 2196420, “Potential information disclosure relating to BW-BEX-ET-WB-7X”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An attacker might gain access to sensitive data for which he/she is not authorized.

Solution

  • SAP NetWeaver 7.0 BW Front End for GUI 730: Import Front-End Patch (FEP) 920 (or higher) for SAP NetWeaver 7.x BW Front End (bi730sp9_920-10004472.exe) into your system. The FEP will be available as soon as SAP Note 1885328 with the short text “SAPBWNews NW 7.x BW Add-On Frontend Patch 920 – GUI 7.30”, which describes this FEP in more detail, is released for customers. This SAP Note might already be available before the FEP is released. You can check the planned availability dates in the attached SAP Note 1085218.
  • SAP NetWeaver 7.0 BW Front End for GUI 740: Import Front-End Patch (FEP) 400 (or higher) for SAP NetWeaver 7.x BW Front End (bi740sp4_400-10004472.exe) into your system. The FEP will be available as soon as SAP Note 2083607 with the short text “SAPBWNews NW 7.x BW Add-On Frontend Patch 400 – GUI 7.40”, which describes this FEP in more detail, is released for customers. This SAP Note might already be available before the FEP is released. You can check the planned availability dates in the attached SAP Note 1085218.

Reason and prerequisites

Unauthorized access to sensitive data.

References

Referenced by

  • 1885328: SAPBWNews NW 7.x BW Add-On Frontend Patch 920 – GUI 7.30

Affected components

  • BIADDON (730 to 730)
  • BIADDON (740 to 740)

Full note on SAP: SAP Support Launchpad note 2196420

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More