SAP security note 1659874, "PI SEC: Missing authorization check in PI Adapter Framework", is a program error note released on December 11, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user assigned to the role SAP_XI_APPL_SERV_USER can use functions of PI Integration Directory or PI Enterprise Services Repository to which access should be restricted. This may result in an escalation of privileges.
Solution
We have changed the rights of the role SAP_XI_APPL_SERV_USER to protect the mentioned applications. Users with this role can no longer use functions to which they shouldn’t have access.
- Patch Levels: please update the software components of the Adapter Engine to the patch levels maintained in the “SP Patch Level” section of this note or use newer versions.
- Resources: the archives and the support package stack guide can be found on the SAP Service Marketplace as described in SAP Note 952402.
Reason and prerequisites
PI Integration Directory and Enterprise Services Repository do not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This may lead to undesired system behavior.
CVSS
Score 0
References
This note refers to
- SAP Note 1823581 – ESR, MESSAGING, SR, UDDI related changes in 7.10 SP16
- SAP Note 1823473 – ESR, SR, UDDI, MESSAGING related changes in 7.11 SP11
- SAP Note 1801016 – SAP EhP2 for Netweaver 7.00 SP13
- SAP Note 1796157 – SAP EhP1 for XI on Netweaver 7.00 SP13
- SAP Note 1795647 – PI CTC: PI Adapter Engine for AEX receives HTTP 403 error
- SAP Note 1792077 – SAP EHP1 FOR SAP NETWEAVER PI 7.1 SP11
- SAP Note 1792074 – SAP Netweaver for PI 7.10 Support Package 16
- SAP Note 1789032 – NW04s XI Support Package Stack 28
- SAP Note 1772043 – PI CTC: HTTP 403 in step "Clears the Directory Cache"
- SAP Note 1759273 – Cache refresh fails
Full note on SAP: SAP Support Launchpad note 1659874
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




