Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing log off functionality in Runtime Workbench, SAP security note 1503582

SAP Note 1503582
SAP Security Note
Medium priority

SAP security note 1503582, "Missing log off functionality in Runtime Workbench", is a note released on April 12, 2011. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > NetWeaver Process Integration (PI) > Integration Server > Runtime Workbench / Monitoring
PriorityCorrection with medium priority
TypeSAP Security Note
Version6
StatusReleased for Customer
Released onApril 12, 2011

Description

Symptom

The SAP XI Runtime Workbench (RWB) user interface does not provide a log off functionality.

Solution

The RWB user interface was improved by providing a log off link. The correction is part of the following and newer Support Packages:

  • XI 3.0 SP27
  • XI 7.0 SP23
  • XI 7.01 SP08
  • XI 7.02 SP06
  • PI 7.10 SP12
  • PI 7.11 SP07

Logging off is performed in two steps:

  • Logging off from all backend systems (Adapter Engines) part of the monitored XI landscape.
  • Logging off from the system where RWB is up and running.

After a successful log off, the standard SAP J2EE Engine log off page is displayed.

Reason and prerequisites

SAP XI Runtime Workbench is the central UI for monitoring entire XI landscapes. It should provide a way to log off the currently logged-in user from all backend systems in use. Logging off users improves security as unattended terminals do not stay active indefinitely and can be used for unauthorized access by third parties.

References

Affected components

  • MESSAGING: from 7.10 to 7.11+
  • SAP_XITOOL: from 7.00 to 7.02+
  • SAP_XITOOL: from 7.10 to 7.11+
  • SAP_XITOOL: from 7.30 to 7.30+
  • SAP_XITOOL: from 7.31 to 7.31+
  • SAP-XIAFC: from 3.0 to 3.0+
  • SAP-XIAFC: from 7.00 to 7.02+

Full note on SAP: SAP Support Launchpad note 1503582

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More