Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized execution of application funcs. in BW-PLA-BPS, SAP security note 1694226

SAP Note 1694226

SAP security note 1694226, "Unauthorized execution of application funcs. in BW-PLA-BPS". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An attacker can execute functions in BW-PLA-BPS without authentication and authorization.

Solution

Implement this SAP Note or import the relevant Support Package.

Also, take the manual post-implementation steps into account when you implement this SAP Note.

Important: The new protection measures take effect only if the HTTPS protocol is selected for the Web interfaces before regeneration. There is no support for HTTP.

Reason and prerequisites

BW-PLA-BPS executes certain functions by referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the authenticated user. The attacker may use a cross-site scripting attack to do this, or they may present a link to the victim.

Ensure that you have implemented SAP Note 1520324 and the other SAP Notes specified there in your system or that your system has the relevant Support Package level.

Affected components

  • SAP_BW (Versions 350 to 731)
  • SAP_BW_VIRTUAL_COMP (Version 701)

Full note on SAP: SAP Support Launchpad note 1694226

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More