SAP security note 1606438, "Unauthorized change of delivered content in BW". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker with special authorizations can manipulate objects in the area of the application component BW-BCT-TCT-IQM to change the displayed application content of another user without authorization, and possibly access authentication information of other legitimate users.
Solution
- SAP NetWeaver BW 7.30: Import Support Package 04 for SAP NetWeaver BW 7.30 (SAPKW73004) into your BW system. This Support Package is available when Note 1583516 "SAPBWNews NW 7.30 BW ABAP SP04" is released for customers.
- SAP NetWeaver BW 7.31 (SAP NW BW 7.0 Enhancement Package 3): Import Support Package 1 for SAP NetWeaver BW 7.31 (SAPKW73101) into your BW system. This Support Package is available when Note 1593298 "SAPBWNews NW BW 7.31/7.03 ABAP SP1" is released for customers.
Urgent Cases: In urgent situations, you can implement the correction instructions as an advance correction. First, read Note 875986, which provides information about transaction SNOTE. Notes mentioned above may already be available before the Support Package is released. In such cases, the short text of the note contains the words "Preliminary version."
Reason and prerequisites
The manipulation of an error message leads to a stored cross-site scripting vulnerability. To execute the manipulation, the attacker must have special authorizations to change configurations and insert malicious code. This type of XSS can be used to permanently modify website content, embed automatically generated malicious content, and steal users’ authentication information. If an administrator’s credentials are compromised, the application’s security may be fully breached.
References
- 1604436 – SAPBWNews BW 7.02 ABAP SP10
- 1601974 – SAPBWNews BW 7.01 ABAP SP11
- 1600222 – SAPBWNews BW 7.00 ABAP SP28
- 1593298 – SAPBWNews BW 7.31 ABAP SP01
- 1583516 – SAPBWNews BW 7.30 ABAP SP04
- 1510977 – SAPBWNews BW 7.11 ABAP SP08
Affected components
- SAP_BW 711
- SAP_BW 730
- SAP_BW 731
Full note on SAP: SAP Support Launchpad note 1606438
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




