PT-2023-4603 · Sap · Sap Bw/4Hana+1

CVE-2023-33992

·

Publicado

2023-07-11

·

Atualizado

2023-07-19

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP Business Warehouse versions SAP BW 730 through SAP BW 750 SAP BW/4HANA versions DW4CORE 100 through DW4CORE 300
Description The issue is related to the SAP BW BICS communication layer, which may expose unauthorized cell values to the data response. To exploit this, a user needs authorizations on the query as well as on the keyfigure/measure level. The missing check only affects the data level. This is due to weaknesses in the authorization procedure, which can allow a remote attacker to gain unauthorized access to protected information.
Recommendations For SAP Business Warehouse versions SAP BW 730 through SAP BW 750, ensure that users have proper authorizations on the query and keyfigure/measure level to minimize the risk of exploitation. For SAP BW/4HANA versions DW4CORE 100 through DW4CORE 300, consider restricting access to sensitive data until a fix is available. As a temporary workaround, consider implementing additional authorization checks on the data level to prevent unauthorized access.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-05010
CVE-2023-33992

Produtos afetados

Sap Bw/4Hana
Sap Business Warehouse