SAP Security Note
Medium priority
SAP security note 1419607, "Security Compliance for XI/PI", is a program error note released on 11.10.2011. Below are the symptom, the SAP recommended solution and the affected software components.
Description
Symptom
This note involves several changes required to comply with the current security product standards for XI/PI.
Solution
Please refer to the details of this note to find out the relevant service package versions.
Reason and prerequisites
Product Standard Conformance. This note provides countermeasures/corrections to protect two assets: business sensitive information and user credentials from unauthorized users.
Protecting business sensitive information: The payload content view of the messaging system monitor is protected by web role (UME action) "content" of application com.sap.aii.af.ms.app. Previously, anyone with the standard monitor user role was able to view not only the message headers but also the message payload contents that may contain business sensitive information.
Protecting credentials: The authorization HTTP header is not persisted with the message. Previously, the complete HTTP headers were persisted including the authentication headers that may reveal user credentials.
CVSS
Score 0
References
This note refers to
Referenced by
Affected components
- MESSAGING 7.10 – 7.11
- MESSAGING 7.20
- MESSAGING 7.30
- SAP_XIAF 7.10 – 7.11
- SAP_XIAF 7.20
- SAP_XIAF 7.30
- SAP-XIAFC 3.0
- SAP-XIAFC 7.00 – 7.02
Full note on SAP: SAP Support Launchpad note 1419607
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




