Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in PI Monitoring, SAP security note 1611926

SAP Note 1611926

SAP security note 1611926, "Missing authorization check in PI Monitoring". Below are the symptom and SAP recommended solution.

Description

Symptom

An authenticated user can use functions of PI Monitoring to which access should be restricted. This may result in an escalation of privileges.

Solution

The authorization checks have been corrected to properly verify permissions for PI Monitoring access. To address this issue, please update the software components of WebAS Java to the Support Packages and patch levels specified in the "SP Patch Level" section of this note, or use newer versions.

For deployments in the 7.3 and 7.3.1 releases, perform the following additional steps for the SOA MONITORS and SOA MONITORS BASIC components:

  • Undeploy DC (Development Component) named tc~pi~editor~perm from SC (Software Component) SOAMON.
  • Undeploy DC named tc~pi~monitor~perm from SC SOAMONBASIC.
  • Update to the latest versions of Software Components SOA MONITORS (SOAMON) and SOA MONITORS BASIC (SOAMONBASIC).

The archives and the support package stack guide are available on the SAP Service Marketplace.

Reason and prerequisites

PI Monitoring does not contain authorization checks for verifying an authenticated user’s permission to access certain functions. This oversight may lead to undesired system behavior.

Full note on SAP: SAP Support Launchpad note 1611926

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More