Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

PI SEC Missing authorization check in PI Adapter Framework, SAP security note 1659874

SAP Note 1659874SAP Security NoteHigh priority

SAP security note 1659874, "PI SEC: Missing authorization check in PI Adapter Framework", is a program error note released on December 11, 2012. Below are the symptom and SAP recommended solution.

ComponentBasis Components > NetWeaver Process Integration (PI) > Connectivity > J2EE Adapter Framework
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onDecember 11, 2012
LanguageEnglish

Description

Symptom

An authenticated user assigned to the role SAP_XI_APPL_SERV_USER can use functions of PI Integration Directory or PI Enterprise Services Repository to which access should be restricted. This may result in an escalation of privileges.

Solution

We have changed the rights of the role SAP_XI_APPL_SERV_USER to protect the mentioned applications. Users with this role can no longer use functions to which they shouldn’t have access.

  • Patch Levels: please update the software components of the Adapter Engine to the patch levels maintained in the “SP Patch Level” section of this note or use newer versions.
  • Resources: the archives and the support package stack guide can be found on the SAP Service Marketplace as described in SAP Note 952402.

Reason and prerequisites

PI Integration Directory and Enterprise Services Repository do not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This may lead to undesired system behavior.

CVSS

Score 0

References

Full note on SAP: SAP Support Launchpad note 1659874

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More