SAP security note 2361633, “SQL Injection vulnerability in SAP Business Intelligence platform”. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP BusinessObjects Business Intelligence platform 4.1 and 4.2 allows an attacker to execute crafted database queries, exposing the backend database.
- Read sensitive data, modify or delete data from the database
- Execute admin level operations on the database
Solution
Prompt answers are checked and attempts of SQL Injection raise invalid response errors.
This issue is fixed in the patches listed in the “Support Packages & Patches” section below. The “Support Packages & Patches” section will be populated with the relevant patch levels once they are released. For Business Intelligence Platform maintenance schedule and strategy, see the Knowledge Base Article 2144559 in the References section.
Reason and prerequisites
Environment: SAP BusinessObjects Business Intelligence platform 4.1 and 4.2
Cause: Prompting in Semantic Layer are not checked correctly. It is possible to build and add SQL statements in addition to the standard prompt answers.
CVSS
Score 6.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Full note on SAP: SAP Support Launchpad note 2361633
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
