Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security check of IPC, SAP security note 658464

SAP Note 658464
SAP Security Note

SAP security note 658464, “Security Check of IPC”, is a note released on 08.10.2009. Below are the SAP recommended solution, affected software components and references.

ComponentCustomer Relationship Management > Internet Pricing and Configurator
TypeSAP Security Note
Version8
StatusReleased for Customer
Released on08.10.2009

Description

Solution

Follow the steps below to enhance the security of your IPC applications:

  • Restrict access rights on the IPC directory to specific users to improve security. See SAP Note 658437, IPC security: Restricting access rights on IPC directory.
  • Check that the security level is set to “1” or higher to run IPC in secure mode. See SAP Note 672421, IPC security: Maintaining the security level.
  • Verify that SAP Note 669883 is applied to set the SECURITY parameter appropriately. See SAP Note 669883, SCE: User entries for attribute with ‘not ready for input’.
  • Maintain an authorization profile for the RFC user associated with IPC. See SAP Note 412309, Authorization profile for RFC user for IPC.
  • Disable remote administration of the IPC server using the IPC Administrator. If remote administration is necessary, ensure a strong password is set. Navigate to the server settings page, unselect the “Remote-Administration” checkbox, save the settings, and restart the IPC Server.
  • Turn off tracing in productive systems: set the trace level to ERROR and configure logging as per the IPC Configuration Support Guide. Refer to IPC Configuration Support, SAP CRM 4.0, “IPC 4.0 Configuration Support”. See SAP Note 646205, Standard logging in IPC 3.0 SP17.
  • Enhance SAP J2EE Engine security: restrict access rights on the J2EE Engine directory (see SAP Note 675125, Securing files containing sensitive data) and disable HTTP-based file browsing by setting DirList to false and restarting the J2EE server (see SAP Note 606733, SAP J2EE – composite SAP note on security of Basis 6.20).
  • Enable secured and authenticated calls from CRM to the IPC server (IPC 4.0 SP05 and higher) by ensuring support for secured socket connections is installed. See SAP Note 698181, IPC security: Maintaining parameters for SNC-RFC connections.
  • Enable secured socket connections for IPC applications (IPC 4.0 SP07 and higher). See SAP Note 720523, IPC security: Maintaining params for SSL secured connections.

For the Internet Sales scenario only:

  • Check the security of Internet Sales applications. See SAP Note 646140, Security Check of Internet Sales.
  • If using Internet Sales with Microsoft Internet Information Server (IIS), verify that the latest security patches are installed. See SAP Note 675043, Security: IIS Security with Microsoft tools.

References

Affected components

  • BBPCRM (300 to 300)
  • BBPCRM (400 to 400)

Full note on SAP: SAP Support Launchpad note 658464

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More