SAP Security Note
High priority
SAP security note 1846945, "Missing authorization check in BPC Web & Web Administration", is a program error note released on 12.11.2013. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of BPC Web and Web Administration to which access should be restricted. This may result in an escalation of privileges.
Solution
You may choose one of the solutions below:
- BPC 7.5 NW: upgrade to SP15 or later.
- BPC 7.5 NW: upgrade to SP14 and apply patch 01 for SP14.
- BPC 7.5 NW: upgrade to SP13 and apply patch 02 for SP13.
- BPC 7.0 NW: update to SP13 Patch01.
Reason and prerequisites
BPC Web and BPC Web Administration do not contain authorization checks for checking an authenticated user's authorization to access some of its functions. This may result in undesired system behavior. However, core functions of BPC Web like Live Reporting, BPF, and System Reports are not vulnerable.
CVSS
Score 6.5 Vector: AV:N/AC:L/AU:S/C:P/I:P/A:P
Full note on SAP: SAP Support Launchpad note 1846945
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



