Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application functions in BW-BCT-PLA-MCB, SAP security note 1706527

SAP Note 1706527

SAP security note 1706527, “Unauthorized Use of Application Functions in BW-BCT-PLA-MCB”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Security Note 1706527 addresses a critical vulnerability in the BW-BCT-PLA-MCB component of SAP Business Warehouse. A malicious user can exploit this vulnerability to execute application functions without proper authentication and authorization. This can lead to unauthorized modification of application content and potential theft of authentication information from legitimate users through Cross-Site Request Forgery (XSRF) and Reflected Cross-Site Scripting (XSS) attacks.

Solution

  • Install Required Notes: Apply SAP Notes 1694226 and 1611670 to your BW system.
  • Configure HTTPS: In the Web Interface (SAPMCBW501), set the property ‘Use HTTPS’ to true. The Web Interface is locked by SAP, so manual changes are not possible.
  • Apply Support Packages: Upgrade to the following BI Content support packages: Release 706: SAPK-70605INBICONT; Release 707: all Support Package levels (SAPK-707xxINBICONT).
  • Upgrade Unsupported Releases: Releases 705, 735, 736, and 746 are out of maintenance and will not receive further support packages. It is strongly recommended to upgrade to BI_CONT 706 or BI_CONT 707.
  • Additional Recommendations: Follow the guidance in SAP Note 733833 (Section: “Web user interface: Modifications in the Web Interface”) to create a copy of the SAPMCBW501 Web interface using transaction BSP_WB.

Reason and prerequisites

  • Unauthorized Access: Attackers can execute functions with the privileges of authenticated users.
  • Data Integrity Risks: Malicious modifications to displayed application content.
  • Credential Theft: Potential theft of user authentication information, allowing impersonation of users, including administrators.

Affected components

  • BI_CONT: Versions 705, 706, 707, 735, 736, 746

Full note on SAP: SAP Support Launchpad note 1706527

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More