SAP NetWeaver Business Warehouse Unauthorized Access Vulnerability
Release date:
Updated on:
Affected Systems:
SAP NetWeaver Business Warehouse
Description:
--------------------------------------------------------------------------------
Bugtraq id: 68955
CVE (CAN) ID: CVE-2014-5174
SAP NetWeaver is the integrated technology platform of SAP and the technical foundation of all SAP applications since SAP Business Suite.
The SAP Netweaver Business Warehouse component does not properly restrict access to functions in the BW-SYS-DB-DB4 function group. authenticated remote attackers can exploit this vulnerability to obtain sensitive information.
<* Source: Nahuel D. S & #195; & #161; nchez
Link: http://xforce.iss.net/xforce/xfdb/94921
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SAP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://service.sap.com/sap/support/notes/1974016
This article permanently updates the link address: