SAP Security Note
High priority
SAP security note 1661698, "Unauthorized modification of displayed content in BW-BEX-ET", is a program error note released on 26.05.2014. Below are the symptom and SAP recommended solution.
Description
Symptom
BW can be exploited by malicious users to modify displayed application content without proper authorization. Additionally, attackers may obtain authentication information from legitimate users, enabling them to impersonate users and access sensitive information.
Solution
Apply the appropriate Support Package based on your SAP NetWeaver BW version:
- SAP NetWeaver BW 7.00: Import Support Package 29 (SAPKW70029). Refer to SAP Note 1658505 for details.
- SAP NetWeaver BW 7.01: Import Support Package 12 (SAPKW70112). Refer to SAP Note 1665768 for details.
- SAP NetWeaver BW 7.02: Import Support Package 12 (SAPKW70212). Refer to SAP Note 1680996 for details.
- SAP NetWeaver BW 7.10: Import Support Package 15 (SAPKW71015).
- SAP NetWeaver BW 7.11: Import Support Package 10 (SAPKW71110). Refer to SAP Note 1665770 for details.
- SAP NetWeaver BW 7.20: Import Support Package 8 (SAPKW72008).
- SAP NetWeaver BW 7.30: Import Support Package 7 (SAPKW73007). Refer to SAP Note 1652579 for details.
- SAP NetWeaver BW 7.31: Import Support Package 3 (SAPKW73103). Refer to SAP Note 1652580 for details. It is recommended to upgrade to SP8 for BW 7.31.
Before applying the correction instructions, ensure you review SAP Note 875986 for transaction SNOTE.
Additionally, implement SAP Note 1582870 for ABAP XSS Escaping Support as a prerequisite.
Reason and prerequisites
Pages within BW-BEX-ET do not sufficiently encode output parameters, resulting in a reflected cross-site scripting (XSS) vulnerability. This allows attackers to deface content or steal session data, compromising the security of the application.
References
Full note on SAP: SAP Support Launchpad note 1661698
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




