Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to users and pwds, SAP security note 1486380

SAP Note 1486380

SAP security note 1486380, "Potential information disclosure relating to users and pwds", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

A malicious user can discover information related to usernames and passwords used in NW PI. This information could be exploited to tailor attacks against NW PI, increasing the risk of unauthorized access and data breaches.

Solution

To mitigate this security vulnerability, follow these steps:

  • Update Exchange Profile Parameter: set the parameter com.sap.aii.ib.remote.exprof.enabled to FALSE, or uncheck the corresponding checkbox if it is of Boolean type. This change helps prevent unauthorized access to sensitive profile information. This parameter is located under the parent IntegrationBuilder in the Exchange Profile.
  • Configure Backend Systems: ensure that all backend systems connected to PI use the RFC-Destination SAP_PROXY_ESR in SPROXY. For SAP Basis release 640, refer to SAP Note 1493325 for additional guidance.
  • Manual Creation of Destinations: manually create the destination CentralMonitoringServer-XIAlerts, as it is no longer created automatically with the update. This destination is essential for sending alerts from Backend Integration Engines.
  • Upgrade Considerations: for upgrades to 730 SP1, follow the same steps as for new installations of 730 SP1. If ensuring that all backend systems use SAP_PROXY_ESR during the upgrade is not feasible, you may temporarily set com.sap.aii.ib.remote.exprof.enabled to TRUE to maintain compatibility.

Reason and prerequisites

The vulnerability arises because information such as usernames and passwords can be discovered if certain security configurations are not properly set within the Exchange Profile.

Full note on SAP: SAP Support Launchpad note 1486380

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More