Advisory
On 10.09.2024 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within BI/BO platform.
SAP Note 3425287 addresses "[CVE-2024-45281] DLL hijacking vulnerability in SAP BusinessObjects Business Intelligence Platform" to prevent missing security function with a medium risk for exploitation.
A workaround does exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance, the team suggests.
Risk specification
Desktop applications of SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to run client applications, resulting in a possible system compromise.Solution
The issue has been resolved by adding an integrity check mechanism for DLLs, which can be activated via a registry key. Circumstances exist that prevent the timely installation of a patch provided by the manufacturer. In such cases, you may consider applying the suggested workaround as a temporary or compensating mitigation: "Update in progress".
Affected System
SAP BusinessObjects Business Intelligence suite is an analytics platform allowing SAP customers to make better decisions based on their business data. SAP BI is a module meant for producing business insights and expands its power in combination with HANA DB and also exists as BW/4 HANA. Due to processing sensitive business data, the Data security is of utmost importance.
The advisory is valid for
- 9.9 [CVE-2021-33698] Unrestricted File Upload vulnerability in SAP Business One
- 7.1 [CVE-2022-39801] Insufficient Firefighter Session Expiration in SAP GRC Access Control Emergency Access Management
- 6.5 [CVE-2024-34683] Unrestricted file upload in SAP Document Builder (HTTP service)
- 6.3 Unauthorized use of application functions in SAP GUI for HTML
- 5.4 [CVE-2020-26816] Missing Encryption in SAP NetWeaver AS Java (Key Storage Service)