Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of application functionality in SAP Exchange Infrastructure, SAP security note 2181460

SAP Note 2181460
SAP Security Note
Medium priority

SAP security note 2181460, "Unauthorized usage of application functionality in SAP Exchange Infrastructure", is a program error note released on 13.09.2016. Below are the symptom, SAP recommended solution and reason and prerequisites.

ComponentBasis Components > NetWeaver Process Integration (PI) > Integration Builder – Configuration
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on13.09.2016
LanguageEnglish

Description

Symptom

An attacker can remotely exploit Integration Builder Directory, potentially consuming resources used to serve PI. Additionally, a security fix may cause cache refresh issues, resulting in the following error in sxi_cache:

"Error ‘HTTP status code 403 Forbidden’ while executing HTTP request (calling method ‘get_status’)"

Solution

Implement the correction instructions by following the manual steps outlined in Manual Activities or by importing the relevant support package. After applying the fix, the ABAP consumer system will retrieve the updated content successfully.

Reason and prerequisites

Usage: the system uses SAP Exchange Infrastructure as the central Integration Server or as the local Integration Engine in an application system.

Issue: the ABAP client accesses the Integration Builder Directory to perform cache refresh. The error occurs due to XSRF protection being enabled.

Full note on SAP: SAP Support Launchpad note 2181460

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More