SAP security note 1922205, “Authorization default value in component BC-XI-IS-WKB”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user of the XI integration server can use functions of component BC-SEC-USR-ADM to which access should be restricted. This may result in an escalation of privileges.
Solution
The Support Packages of this SAP Note correct the default values for transaction SXMB_MONI_BPE. You can upload the authorization default values in advance from the files <Rel>_SU22_SXMB_MONI_BPE.txt attached to this note. For example, file 700_SU22_SXMB_MONI_BPE.txt corresponds to Release SAP_BASIS 700.
To upload the files, use the Upload function in the application toolbar of transaction SU24 as described in SAP Note 1539556 – FAQ | Administration of authorization default values. Also refer to the description in SAP Note 368496 regarding the upload procedure; pay particular attention to the details for the parameters "Copy SAP Data to Customer Tables" and "Replace Instd of Insert/Modify".
Reason and prerequisites
Roles are created from the authorization default values for transaction SXMB_MONI_BPE, among other things.
References
Affected components
- SAP_BASIS (640)
- SAP_BASIS (700 – 702)
- SAP_BASIS (710 – 711)
- SAP_BASIS (730)
- SAP_BASIS (731)
- SAP_BASIS (740)
Full note on SAP: SAP Support Launchpad note 1922205
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




