SAP security note 1826001, "Potential remote code execution in Webi Rich Client", is a note. Below are the symptom, SAP recommended solution and affected software components.
Description
Symptom
A malicious user can exploit Web Intelligence Rich Client to enable them to execute arbitrary code in the product.
Solution
Apply one of the following patches:
- BI XIr3 FixPack 5.5 or FixPack 6.1
- BI4 Patch 4.12, Patch 5.5, or Support Pack 6
Reason and prerequisites
A code execution vulnerability exists in Web Intelligence Rich Client. This enables a malicious user to inject code into the working memory that is subsequently executed by the application. It can also be used to cause a general fault in the product, causing the product to terminate.
Affected components
- BOEWEBAPPJAVA: 3.1 to 3.1+
Full note on SAP: SAP Support Launchpad note 1826001
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




