Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SBOP solution for Apache Struts1.x Vulnerability CVE-2014-0094, SAP security note 2026174

SAP Note 2026174

SAP security note 2026174, “SBOP solution for Apache Struts1.x Vulnerability CVE-2014-0094”. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBI-BIP-INV

Description

Symptom

UPDATE 24th November: This note has been re-released with updated CVSS details and Solution information.

The ParametersInterceptor in Apache Struts versions earlier than 2.3.16.3 allows remote attackers to manipulate the ClassLoader via the class parameter, which is passed to the getClass method. This vulnerability can be exploited to manipulate resources used to serve BI Launchpad, LCM, and Monitoring.

Solution

This vulnerability has been fixed by modifying configurations related to the Struts Framework. The fix has been delivered with the following updates:

  • SAP BusinessObjects Enterprise XI3.1: Refer to the “Hotfix for XI3.1 FixPack 6.4” on the SAP Service Market Place.
  • SAP BusinessObjects Enterprise XI3.1 FP7.1
  • SAP BusinessObjects Enterprise XI4.0 FP8.9 and FP9.5
  • SAP BusinessObjects Enterprise XI4.0 SP10
  • SAP BusinessObjects Enterprise XI4.1 FP1.11, FP2.9, FP3.4, FP4.1

Reason and prerequisites

An attacker can infiltrate the application through vulnerabilities in the Struts framework, allowing malicious code injection to consume resources unnecessarily.

CVSS

Score 7.5 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

Affected components

  • ENTERPRISE XI 3.1, 4.0, 410

Full note on SAP: SAP Support Launchpad note 2026174

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More