Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Display Stack Trace in Error Pages, SAP security note 1122437

SAP Note 1122437

SAP security note 1122437, "Display Stack Trace in Error Pages", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

You are using a BEx Web Application NW 7.0 Java. If an error occurs in the Web Application, a detailed error page is displayed including the error stack trace.

You would like to disable the stack trace from being displayed on error pages.

Solution

To disable the stack trace in error pages, perform the following steps:

  • Implement the SPS level and patch level as described in Note 1121970.
  • Modify the BEx Web NW 7.0 iViews: navigate to Content Administration > Portal Content > Browse > Portal Content > Content Provided by SAP > Platform Add-Ons > Business Intelligence > iViews. Add DISPLAY_STACK_TRACE_IN_ERROR_PAGES=false to the Application Parameters of the iViews pcd:portal_content/com.sap.pct/platform_add_ons/com.sap.ip.bi/iViews/comsap.ip.bi.bex and pcd:portal_content/com.sap.pct/platform_add_ons/com.sap.ip.bi/iViews/comsap.ip.bi.bexwebanalyzer and save the modifications (see attachment error_pages_bex_iviews.zip as well).

References

Affected components

  • SAP_BW 700 to 701+
  • SAP_BW 710 to 711

Full note on SAP: SAP Support Launchpad note 1122437

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More