The SAP BW BICS communication layer in SAP Business Warehouse and SAP BW/4HANA - version SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 730, SAP_BW 750, DW4CORE 100, DW4CORE 200, DW4CORE 300, may expose unauthorized cell values to the data response. To be able to exploit this, the user still needs authorizations on the query as well as on the keyfigure/measure level. The missing check only affects the data level.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Business_warehouse | Sap | 730 (including) | 730 (including) |
Business_warehouse | Sap | 731 (including) | 731 (including) |
Business_warehouse | Sap | 740 (including) | 740 (including) |
Business_warehouse | Sap | 750 (including) | 750 (including) |
Bw/4hana | Sap | 100 (including) | 100 (including) |
Bw/4hana | Sap | 200 (including) | 200 (including) |
Bw/4hana | Sap | 300 (including) | 300 (including) |
Assuming a user with a given identity, authorization is the process of determining whether that user can access a given resource, based on the user’s privileges and any permissions or other access-control specifications that apply to the resource. When access control checks are not applied, users are able to access data or perform actions that they should not be allowed to perform. This can lead to a wide range of problems, including information exposures, denial of service, and arbitrary code execution.