SAP security note 1638660, “Potential information disclosure relating to PAF Monitor”. Below are the symptom and SAP recommended solution.
Description
Symptom
An information disclosure vulnerability has been identified in the PAF Monitor used to monitor documents sent through SAP PI. An attacker could exploit this vulnerability to gather information about the PAF Monitor, which may help them tailor their attacks against SAP systems and applications.
- Information about the PAF Monitor being used is exposed.
- Potential attackers can discover distributed business use cases implemented via the PAF Monitor.
Exploiting this vulnerability allows attackers to gain insights into the SAP system’s configuration, enabling more targeted and potentially more damaging attacks.
Solution
To mitigate this vulnerability, follow the steps below to deactivate unnecessary services or apply the relevant support packages:
Deactivate Unnecessary Services: If the "/sap/bc/webdynpro/sap/spaf_monitoring" service is not required, ensure it is deactivated using transaction SICF:
- Step 1: Call transaction SICF.
- Step 2: In the Service Path field, enter /sap/bc/webdynpro/sap/spaf_monitoring.
- Step 3: Click on the Execute button (F8).
- Step 4: For all Virtual Hosts, select (double-click) the service leaf spaf_monitoring.
- Step 5: Click on the Change button (Ctrl+F1).
- Step 6: In the SAP Authoriz. field (located on the first tab labeled ‘Service Data’), enter PAFADM.
- Step 7: Click on the Save button (Ctrl+S).
Repeat the above procedure for the following service names:
- spaf_pip_browser (BXI000287)
- spaf_agents_browser (BXI000358)
- spaf_error_handling (BXI000478)
- spaf_monitoring_msgid (BXI000776)
- spaf_agents_config (BXI000960)
- spaf_bpa_main
- spaf_config
- spaf_home
- spaf_test_docs
Do not be confused if the Service Name starts with BXI instead of spaf_. Alternative names are equivalent and listed above.
Full note on SAP: SAP Support Launchpad note 1638660
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
