SAP Security Note
Medium priority
SAP security note 1503582, "Missing log off functionality in Runtime Workbench", is a note released on April 12, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The SAP XI Runtime Workbench (RWB) user interface does not provide a log off functionality.
Solution
The RWB user interface was improved by providing a log off link. The correction is part of the following and newer Support Packages:
- XI 3.0 SP27
- XI 7.0 SP23
- XI 7.01 SP08
- XI 7.02 SP06
- PI 7.10 SP12
- PI 7.11 SP07
Logging off is performed in two steps:
- Logging off from all backend systems (Adapter Engines) part of the monitored XI landscape.
- Logging off from the system where RWB is up and running.
After a successful log off, the standard SAP J2EE Engine log off page is displayed.
Reason and prerequisites
SAP XI Runtime Workbench is the central UI for monitoring entire XI landscapes. It should provide a way to log off the currently logged-in user from all backend systems in use. Logging off users improves security as unattended terminals do not stay active indefinitely and can be used for unauthorized access by third parties.
References
- ESR, SR, UDDI, MESSAGING related changes in 7.10 SP12
- SAP EhP1 for XI on Netweaver 7.00 SP08
- NW04s XI Support Package Stack 23
- XI 30 Support Package Stack (SPS) 27
- SAP EhP2 for Netweaver 7.00 SP06
Affected components
- MESSAGING: from 7.10 to 7.11+
- SAP_XITOOL: from 7.00 to 7.02+
- SAP_XITOOL: from 7.10 to 7.11+
- SAP_XITOOL: from 7.30 to 7.30+
- SAP_XITOOL: from 7.31 to 7.31+
- SAP-XIAFC: from 3.0 to 3.0+
- SAP-XIAFC: from 7.00 to 7.02+
Full note on SAP: SAP Support Launchpad note 1503582
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
