Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Authorization default value in component BC-XI-IS-WKB, SAP security note 1922205

SAP Note 1922205

SAP security note 1922205, “Authorization default value in component BC-XI-IS-WKB”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An authenticated user of the XI integration server can use functions of component BC-SEC-USR-ADM to which access should be restricted. This may result in an escalation of privileges.

Solution

The Support Packages of this SAP Note correct the default values for transaction SXMB_MONI_BPE. You can upload the authorization default values in advance from the files <Rel>_SU22_SXMB_MONI_BPE.txt attached to this note. For example, file 700_SU22_SXMB_MONI_BPE.txt corresponds to Release SAP_BASIS 700.

To upload the files, use the Upload function in the application toolbar of transaction SU24 as described in SAP Note 1539556 – FAQ | Administration of authorization default values. Also refer to the description in SAP Note 368496 regarding the upload procedure; pay particular attention to the details for the parameters "Copy SAP Data to Customer Tables" and "Replace Instd of Insert/Modify".

Reason and prerequisites

Roles are created from the authorization default values for transaction SXMB_MONI_BPE, among other things.

References

Affected components

  • SAP_BASIS (640)
  • SAP_BASIS (700 – 702)
  • SAP_BASIS (710 – 711)
  • SAP_BASIS (730)
  • SAP_BASIS (731)
  • SAP_BASIS (740)

Full note on SAP: SAP Support Launchpad note 1922205

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More