SAP security note 1122437, "Display Stack Trace in Error Pages", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
You are using a BEx Web Application NW 7.0 Java. If an error occurs in the Web Application, a detailed error page is displayed including the error stack trace.
You would like to disable the stack trace from being displayed on error pages.
Solution
To disable the stack trace in error pages, perform the following steps:
- Implement the SPS level and patch level as described in Note 1121970.
- Modify the BEx Web NW 7.0 iViews: navigate to Content Administration > Portal Content > Browse > Portal Content > Content Provided by SAP > Platform Add-Ons > Business Intelligence > iViews. Add DISPLAY_STACK_TRACE_IN_ERROR_PAGES=false to the Application Parameters of the iViews pcd:portal_content/com.sap.pct/platform_add_ons/com.sap.ip.bi/iViews/comsap.ip.bi.bex and pcd:portal_content/com.sap.pct/platform_add_ons/com.sap.ip.bi/iViews/comsap.ip.bi.bexwebanalyzer and save the modifications (see attachment error_pages_bex_iviews.zip as well).
References
Affected components
- SAP_BW 700 to 701+
- SAP_BW 710 to 711
Full note on SAP: SAP Support Launchpad note 1122437
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
