SAP Security Note
High priority
SAP security note 1607845, "Unauthorized modification of displayed content in BW-BEX-ET", released on 13.09.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
The BW-BEX could be abused by a malicious user, who could modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.
Solution
SAP NetWeaver BW 7.00: Import Support Package 28 for SAP NetWeaver BW 7.00 (SAPKW70028) into your BW system. The Support Package will be available as soon as note 1600222 with the short text "SAPBWNews NW BW 7.0 ABAP SP28", which describes this Support Package in more detail, is released for customers.
SAP NetWeaver BW 7.01 (SAP NW BW7.0 EnhP 1): Import Support Package 11 for SAP NetWeaver BW 7.01 (SAPKW70111) into your BW system. The Support Package will be available as soon as note 1601974 with the short text "SAPBINews NW7.01 BW ABAP SP11", which describes this Support Package in more detail, is released for customers.
SAP NetWeaver BW 7.02 (SAP NW BW7.0 EnhP 2): Import Support Package 10 for SAP NetWeaver BW 7.02 (SAPKW70210) into your BW system. The Support Package will be available as soon as note 1604436 with the short text "Prelimenary Version SAPBWNews NW BW 7.02 ABAP SP10", which describes this Support Package in more detail, is released for customers.
SAP NetWeaver BW 7.11: Import Support Package 08 for SAP NetWeaver BW 7.11 (SAPKW71108) into your BW system. The Support Package will be available as soon as SAP note 1510977 with the short text "Prelimenary Version SAPBINews NW7.11 BW ABAP SP8", which describes this Support Package in more detail, is released for customers.
SAP NetWeaver BW 7.30: Import Support Package 05 for SAP NetWeaver BW 7.30 (SAPKW73005) into your BW system. The Support Package will be available as soon as note 1606526 with the short text "SAPBWNews NW7.30 BW ABAP SP05", which describes this Support Package in more detail, is released for customers.
SAP NetWeaver BW 7.31 (SAP NW BW7.0 EnhP 3): Import Support Package 1 for SAP NetWeaver BW 7.31 (SAPKW73101) into your BW system. The Support Package will be available as soon as note 1593298 with the short text "Prelimenary Version SAPBWNews NW BW 7.31/7.03 ABAP SP1", which describes this Support Package in more detail, is released for customers.
You can use the correction instructions to implement correction before the Support Package. Beforehand, definitely check SAP Note 875986 for transaction SNOTE.
This note might already be available before the Support Package is released. In this case, however, the short text still contains the terms "preliminary version".
Reason and prerequisites
Pages within the BW-BEX do not sufficiently encode OUTPUT parameters, resulting in a reflected cross-site scripting issue. A reflected cross-site scripting attack can be used to non-permanently deface or modify displayed content from a website.
Reflected cross-site scripting can be used to steal another user’s authentication information, such as data relating to their current session. An attacker who gains access to this data could use it to impersonate the user and access all information with the same rights as the target user. If an administrator is impersonated, the application’s security could be fully compromised.
Full note on SAP: SAP Support Launchpad note 1607845
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
