SAP Security Note
Medium priority
SAP security note 1441945, "Authorization check incomplete in XI/PI administration", released on 19.03.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A flaw in the authorization check implementation allows users without sufficient authorization to execute certain XI/PI administration and monitoring functions in the Integration Engine. The affected functions include:
- Monitor for messages in MultiMessageFormat
- Restarting messages
- Confirming messages
- Configuring and executing the queue monitor in XI/PI
- Configuring and monitoring package statistics
- Configuring the work process monitor in XI/PI
Solution
Apply the relevant Support Package or implement the Correction Instructions provided in this note.
Note: After applying the corrections, if you have scheduled the report RSXMB_RESTART_MESSAGES as a background job to restart messages, ensure that the user executing the report has sufficient authorization.
Affected components
- SAP NetWeaver 2004
- SAP NetWeaver 2004S
- SAP Enhancement Package 1 for SAP NetWeaver 7.0
- SAP Enhancement Package 2 for SAP NetWeaver 7.0
- SAP NetWeaver PI 7.1
- SAP Enhancement Package 1 for SAP PI NetWeaver 7.1
- All subsequent releases
Full note on SAP: SAP Support Launchpad note 1441945
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



