SAP Security Note
High priority
SAP security note 1600404, "Authentication for CPACache webpage", is a program error note released on March 13, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
A JSP page in SAP PI – http://<host>:<port>/CPACache/testconfigupload.jsp can be accessed without providing authentication.
Solution
Authentication is provided for the http://<host>:<port>/CPACache/testconfigupload.jsp and a user needs to have the role XI_AF_CPA_INVALIDATE to access the JSP page.
Reason and prerequisites
The http://<host>:<port>/CPACache/testconfigupload.jsp is useful for error analysis and used for internal purposes for support reasons, but it can possibly override actual configuration data.
Full note on SAP: SAP Support Launchpad note 1600404
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




