Medium priority
SAP security note 2288310, “Vulnerability in BusinessObjects components related to Xalan”, is a note released on October 11, 2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Several BusinessObjects components were using a vulnerable version of Apache Xalan.
Solution
This issue is fixed in the patches listed in the “Support Packages & Patches” section below. The “Support Packages & Patches” section will be populated with the relevant patch levels once they are released. For Business Intelligence Platform maintenance schedule and strategy, see Knowledge Base Article 2144559.
CVSS
Score 6.3/10 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected components
- Business Mobile > Mobile Applications > Business Intelligence Mobile > Mobile BI Server (MOB-APP-BI-SRV)
- Business intelligence solutions > Business intelligence platform > BI Servers, security, Crystal Reports in Launchpad (BI-BIP-ADM)
- Business intelligence solutions > Business intelligence platform > Installation, Updates, Upgrade, Patching (BI-BIP-INS)
- Business intelligence solutions > Business intelligence platform > BI Workspaces (Dashboard Builder) (BI-BIP-BIW)
- Business intelligence solutions > Reporting, analysis, and dashboards > Analysis, edition for OLAP (Web) (BI-RA-AWB)
- Business intelligence solutions > Business intelligence platform > BI platform monitoring (BI-BIP-MON)
- Business intelligence solutions > Reporting, analysis, and dashboards > Web Intelligence (BI-RA-WBI)
- Business intelligence solutions > Reporting, analysis, and dashboards > Obsolete: Polestar, Explorer (BI-RA-EXP)
Full note on SAP: SAP Support Launchpad note 2288310
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
