Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Server-Side Request Forgery (SSRF) vulnerability in Web Intelligence BI Launchpad, SAP security note 2428512

SAP Note 2428512

SAP security note 2428512, "Server-Side Request Forgery (SSRF) vulnerability in Web Intelligence BI Launchpad". Below are the symptom and SAP recommended solution.

Description

Symptom

Web Intelligence BI Launchpad allows an attacker who has already gained access to the BI platform to remotely force the application server to make HTTP requests to inappropriate URLs.

  • Creates requests from the vulnerable server to intranet/internet.
  • SSRF usually attacks targets on the internal systems that are located behind a firewall and normally inaccessible from the outside world.
  • With SSRF, it’s possible to access these systems.

Solution

Web Intelligence BI Launchpad checks the MIME type of the requested resources to cancel requests for serving files where an image should normally be returned.

This issue is fixed in the patches listed in the "Support Packages & Patches" section below.

For Business Intelligence Platform maintenance schedule and strategy, see the Knowledge Base Article 2144559 – BI 4.x Maintenance Strategy & Schedule.

Reason and prerequisites

An attacker can trick Web Intelligence BI Launchpad to access intranet server resources in place of downloading an image. Attacker needs to have gained editing privileges in order to modify documents prior to exploiting this vulnerability.

CVSS

Score 5.0 Vector: AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

References

Full note on SAP: SAP Support Launchpad note 2428512

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More