Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Authentication for CPACache webpage, SAP security note 1600404

SAP Note 1600404
SAP Security Note
High priority

SAP security note 1600404, "Authentication for CPACache webpage", is a program error note released on March 13, 2012. Below are the symptom and SAP recommended solution.

ComponentBasis Components > NetWeaver Process Integration (PI) > Connectivity > J2EE Adapter Framework > Directory Cache
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released onMarch 13, 2012
LanguageEnglish

Description

Symptom

A JSP page in SAP PI – http://<host>:<port>/CPACache/testconfigupload.jsp can be accessed without providing authentication.

Solution

Authentication is provided for the http://<host>:<port>/CPACache/testconfigupload.jsp and a user needs to have the role XI_AF_CPA_INVALIDATE to access the JSP page.

Reason and prerequisites

The http://<host>:<port>/CPACache/testconfigupload.jsp is useful for error analysis and used for internal purposes for support reasons, but it can possibly override actual configuration data.

Full note on SAP: SAP Support Launchpad note 1600404

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More

Three identical server cabinets carrying stacks of code of very different heights beside a measuring rule

ABAP Code Security Scan Cost Drivers

What moves the cost of an ABAP code security scan: custom object counts, effective lines, systems in scope, transport gating, triage and retest.