Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential modification / disclosure of persisted data in BW-WHM-DBA, SAP security note 1965819

SAP Note 1965819

SAP security note 1965819, "Potential Modification/Disclosure of Persisted Data in BW-WHM-DBA". Below are the symptom, SAP recommended solution and the affected software components.

ComponentSAP Business Warehouse > Data Warehouse Management > Data Basis (BW-WHM-DBA)

Description

Symptom

A critical SQL injection vulnerability has been identified in SAP BW-WHM-DBA. This vulnerability allows an attacker to send specially crafted inputs to modify database commands, potentially leading to unauthorized retrieval or modification of persisted data within the system.

Solution

  • Import the relevant support packages for your SAP NetWeaver BW version once they are released.
  • Before the support packages are available, you can apply the correction instructions provided in SAP Security Note 1965819. Ensure to review SAP Note 1668882 using transaction SNOTE before applying the corrections.

CVSS

Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P

Affected components

  • SAP NetWeaver BW 7.00
  • SAP NetWeaver BW 7.01 (EHP 1)
  • SAP NetWeaver BW 7.02 (EHP 2)
  • SAP NetWeaver BW 7.11
  • SAP NetWeaver BW 7.20

Full note on SAP: SAP Support Launchpad note 1965819

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More