Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Authorization check incomplete in XI/PI administration, SAP security note 1441945

SAP Note 1441945
SAP Security Note
Medium priority

SAP security note 1441945, "Authorization check incomplete in XI/PI administration", released on 19.03.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > NetWeaver Process Integration (PI) > Integration Server > Integration Engine
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on19.03.2010

Description

Symptom

A flaw in the authorization check implementation allows users without sufficient authorization to execute certain XI/PI administration and monitoring functions in the Integration Engine. The affected functions include:

  • Monitor for messages in MultiMessageFormat
  • Restarting messages
  • Confirming messages
  • Configuring and executing the queue monitor in XI/PI
  • Configuring and monitoring package statistics
  • Configuring the work process monitor in XI/PI

Solution

Apply the relevant Support Package or implement the Correction Instructions provided in this note.

Note: After applying the corrections, if you have scheduled the report RSXMB_RESTART_MESSAGES as a background job to restart messages, ensure that the user executing the report has sufficient authorization.

Affected components

  • SAP NetWeaver 2004
  • SAP NetWeaver 2004S
  • SAP Enhancement Package 1 for SAP NetWeaver 7.0
  • SAP Enhancement Package 2 for SAP NetWeaver 7.0
  • SAP NetWeaver PI 7.1
  • SAP Enhancement Package 1 for SAP PI NetWeaver 7.1
  • All subsequent releases

Full note on SAP: SAP Support Launchpad note 1441945

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More