cancel
Showing results for 
Search instead for 
Did you mean: 

Please cearify 3421384 Information Disclosure vulnerability in SAP BusinessObjects Web Intelligence

Martin_4
Participant
0 Kudos
387

intentionaly empty

Martin_4
Participant
0 Kudos

Suma Sum:

What is the  Excel Data Access Service for ?
In short:
-it enables You only to build a Webi on top of an Excel, loaded into the BO Content.
-it has no impact on downloading, exporting excels (or PDFs) with data from a BO Applications
-it has no impact on Webi Applcations on top of Excel, loaded into the BO Content, already build,
these still work with or without Excel Data Access Service

How to check Excel Data Access Service functionality
and / or build a BO Server without  Excel Data Access Service ?
-Logged in with SAP or Enterprise Authentification

A) Build a Test Case 
-upload an Excel to the BO Content Server,
-build a Webi Application on top of it and execute it,
-if You dont have an error while building, You have a Excel Data Access Service in one of the BO Servers,
-generating a Webi or a Lumira and exporting the results  to Excel or PDF is working

B)Find the BO Server with the Data Access Service "switched" on:
-Go to through all Your servers, an check the Common Services for Excel Data Access Service
For example: Adaptive Processing Server, M...14.APS.WebI,

C) Set up a BO server without ExcelData Access Service to see whats working not
-its in BO technically not possible to delete or remove an Excel Data Access Service in an existing BO Server,
-its also in BO technically not possible to delete or remove an Excel Data Access Service in a Clone of an  existing BO Server,
-you must make a new BO Server without of the Excel Data Access Service and than
 shutdown the existing BO Server (with the  Excel Data Access Service) (and best mark it as inactive).

D) Test You Excel BO Content based webi again
-with the (all) Excel Data Access Service not beeing active in a BO Server its not more possible to
build a Webi Application (or other) on top of an Excel loaded into the BO Content,
-Webi Creates an Error: Fehler im Server. Interner Fehler beim Aufruf von 'processDPCommandsEx' API. (Fehler: ERR_WIS_30270)

 -existing Webis, based on Excel in the BO Conetnt still run
-export of Excel in any BO Application still works

What does this mean for the 3421384 if You build a BO Server without of the Excel Data Access Service :
-
Existing Webis on base of an Excel can still be used
-Export of an Webi Application to PDF or Excel is still possible
-You might face risks according to 3421384 in Your existing BO Content Excels
(what means these may contain code to read out the BO Server)
 
 
Martin_4_0-1723037840282.png
Martin_4_1-1723037840283.png

 

Replies (0)
View Entire Topic
BasicTek
Advisor
Advisor
0 Kudos

It's used for webi reports that are based of Excel as a data source vs SQL, BW, Oracle, etc

 

https://launchpad.support.sap.com/#/notes/1709797

Martin_4
Participant
0 Kudos

Intentionaly empty