SAP security note 1448266, "Missing authentication check in MessageSearch service". Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can use functions of the MessageSearch Service to which access should be restricted. This may result in an escalation of privileges.
Solution
MessageSearch service is no longer accessible to unauthorized users. Users need to have the role SAP_XI_MONITOR_J2EE in order to access the MessageSearch service. Kindly check the SP/PL information and apply the relevant patch.
Reason and prerequisites
The MessageSearch Service is missing authentication steps. This may result in undesired system behavior.
References
Full note on SAP: SAP Support Launchpad note 1448266
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
