Skip links
Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Removal of Hidden menus and Developer mode in ESR, SAP security note 1711728

Description

In Enterprise services repository (ESR) or in Directory, there is a way to switch on the Developer mode and some hidden menus intended for developers only are available in the message mapping editor.

Available fix and Supported packages

  • SAP_XIESR | 7.10 | 7.11
  • SAP_XIESR | 7.20 | 7.20
  • SAP_XIESR | 7.31 | 7.31
  • SAP_XITOOL | 7.00 | 7.02
  • SAP_XITOOL | 7.10 | 7.11
  • SAP_XITOOL | 7.20 | 7.20
  • SAP_XITOOL | 7.30 | 7.30
  • SAP_XITOOL | 7.31 | 7.31
  • SAP_XIGUILIB | 7.20 | 7.20
  • SAP_XIGUILIB | 7.30 | 7.30
  • SAP_XIGUILIB | 7.31 | 7.31
  • ESR 7.10 | SP009 | 000021
  • ESR 7.10 | SP010 | 000013
  • ESR 7.10 | SP011 | 000010
  • ESR 7.10 | SP012 | 000004
  • ESR 7.10 | SP013 | 000000
  • ESR 7.11 | SP005 | 000023
  • ESR 7.11 | SP006 | 000016
  • ESR 7.11 | SP007 | 000005
  • ESR 7.11 | SP008 | 000000
  • ESR 7.11 | SP009 | 000000
  • ESR 7.11 | SP010 | 000000
  • ESR 7.30 | SP000 | 000003
  • ESR 7.30 | SP001 | 000009
  • ESR 7.30 | SP002 | 000013
  • ESR 7.30 | SP003 | 000006
  • ESR 7.30 | SP004 | 000003
  • ESR 7.30 | SP005 | 000002
  • ESR 7.31 | SP002 | 000000
  • PI GUI LIBRARY 7.20 | SP003 | 000002
  • PI GUI LIBRARY 7.20 | SP004 | 000003

Affected component

    BC-XI-IBD-MAP
    Integration Builder Design – Mapping

CVSS

Score: 0

PoC

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1711728

TAGS

#Enterprise-Services-Repository
#ESR
#Directory
#XI
#PI
#Alt+F7
#Developer-mode
#Message-Mapping
#Mapping-Template
#Ctrl+Shift+0
#Last-Used
#Import
#Export
#xim

Explore More

SAP Security Patch Day RedRays

SAP Security Patch Day – April 2025

On April 8, 2025, SAP released its monthly Security Patch Day updates, addressing 19 new vulnerabilities across various SAP products and components.

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.