Skip links
Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Removal of Hidden menus and Developer mode in ESR, SAP security note 1711728

Description

In Enterprise services repository (ESR) or in Directory, there is a way to switch on the Developer mode and some hidden menus intended for developers only are available in the message mapping editor.

Available fix and Supported packages

  • SAP_XIESR | 7.10 | 7.11
  • SAP_XIESR | 7.20 | 7.20
  • SAP_XIESR | 7.31 | 7.31
  • SAP_XITOOL | 7.00 | 7.02
  • SAP_XITOOL | 7.10 | 7.11
  • SAP_XITOOL | 7.20 | 7.20
  • SAP_XITOOL | 7.30 | 7.30
  • SAP_XITOOL | 7.31 | 7.31
  • SAP_XIGUILIB | 7.20 | 7.20
  • SAP_XIGUILIB | 7.30 | 7.30
  • SAP_XIGUILIB | 7.31 | 7.31
  • ESR 7.10 | SP009 | 000021
  • ESR 7.10 | SP010 | 000013
  • ESR 7.10 | SP011 | 000010
  • ESR 7.10 | SP012 | 000004
  • ESR 7.10 | SP013 | 000000
  • ESR 7.11 | SP005 | 000023
  • ESR 7.11 | SP006 | 000016
  • ESR 7.11 | SP007 | 000005
  • ESR 7.11 | SP008 | 000000
  • ESR 7.11 | SP009 | 000000
  • ESR 7.11 | SP010 | 000000
  • ESR 7.30 | SP000 | 000003
  • ESR 7.30 | SP001 | 000009
  • ESR 7.30 | SP002 | 000013
  • ESR 7.30 | SP003 | 000006
  • ESR 7.30 | SP004 | 000003
  • ESR 7.30 | SP005 | 000002
  • ESR 7.31 | SP002 | 000000
  • PI GUI LIBRARY 7.20 | SP003 | 000002
  • PI GUI LIBRARY 7.20 | SP004 | 000003

Affected component

    BC-XI-IBD-MAP
    Integration Builder Design – Mapping

CVSS

Score: 0

PoC

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1711728

TAGS

#Enterprise-Services-Repository
#ESR
#Directory
#XI
#PI
#Alt+F7
#Developer-mode
#Message-Mapping
#Mapping-Template
#Ctrl+Shift+0
#Last-Used
#Import
#Export
#xim

Explore More

RedRays AI for ABAP Code Security

Empowering Secure, Efficient, and Compliant SAP ABAP Development—in Real Time and Without Data Retention In today’s rapidly evolving business landscape, organizations increasingly

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.