Medium priority
SAP security note 1645844, "PI SEC: Missing Authorization Check in Integration Builder", is released on August 14, 2012. Below are the symptom, SAP recommended solution, reason and references for this note.
Description
Symptom
An authenticated user can access functions of the Integration Builder Directory that should be restricted, potentially leading to an escalation of privileges.
Solution
Update your XI/PI System to the recommended versions and patch levels specified in this note. This update includes the necessary authorization checks to secure the Integration Builder Directory.
Reason and prerequisites
The Integration Builder Directory lacks necessary authorization checks to verify a user’s permissions when accessing certain functions, which may result in undesired system behavior.
References
- SAP Note 1834355: PI SEC: Warning when creating roles SAP_XI_CONFIG_FILE_*
- SAP Note 1740004: SAP EhP2 for Netweaver 7.00 SP12
- SAP Note 1730853: SAP EhP1 for XI on Netweaver 7.00 SP12
Full note on SAP: SAP Support Launchpad note 1645844
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




