SAP security note 1939673, "Potential information disclosure relating to planning or consolidation transaction data", is a note. Below are the symptom, SAP recommended solution and affected software components.
Description
Symptom
An attacker can discover information relating to planning or consolidation transaction data in BPC NW. This information could be used to allow the attacker to specialize their attacks against planning or consolidation.
Solution
Apply the program correction instructions of this note or upgrade to the corresponding support package, so that characteristics for newly secured dimensions are automatically marked to be authorization relevant.
For existing secure dimensions, you need to manually use transaction RSA1 or RSD1 to mark the corresponding characteristics.
Reason and prerequisites
This is caused by a program error. It is only relevant for BPC NW release 10 or 10.1. Information disclosure may happen only if you have already granted an attacker necessary BW authorizations (e.g., S_RS_COMP) to access the BW objects which are generated by BPC.
CVSS
Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N
References
Affected components
- CPMBPC: 800, 801, 810
Full note on SAP: SAP Support Launchpad note 1939673
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




