SAP security note 1607850, "Potential Information Disclosure Relating to BW". Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can discover information relating to SAP Business Warehouse (BW). This information could be used to tailor attacks specifically against BW systems.
Solution
To address this vulnerability, apply the appropriate Support Package for your SAP NetWeaver BW version:
- SAP NetWeaver BW 7.00: import Support Package 28 (SAPKW70028)
- SAP NetWeaver BW 7.01: import Support Package 11 (SAPKW70111)
- SAP NetWeaver BW 7.02: import Support Package 10 (SAPKW70210)
- SAP NetWeaver BW 7.11: import Support Package 08 (SAPKW71108)
- SAP NetWeaver BW 7.30: import Support Package 05 (SAPKW73005)
- SAP NetWeaver BW 7.31: import Support Package 01 (SAPKW73101)
Before applying any corrections, ensure you review SAP Note 875986 using transaction SNOTE.
Reason and prerequisites
Sensitive information such as user passwords can be exposed through BW. This exposure can be exploited by malicious actors to target and potentially corrupt BW systems.
CVSS
Score 7.5 Vector: AV:N/AC:L/AU:S/C:N/I:P/A:C
Full note on SAP: SAP Support Launchpad note 1607850
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
