Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security note Security gap in ACO_BSP_ADMIN, SAP security note 1229303

SAP Note 1229303
SAP Security Note
High priority

SAP security note 1229303, "Security gap in ACO_BSP_ADMIN", released on 03.02.2011. Below are the symptom and the SAP recommended solution.

PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released on03.02.2011

Description

Symptom

In BSP application ACO_BSP_ADMIN you can change the search help URL to any search help that exists in the system.

Solution

cProjects 4.0
Use Web Dynpro application DPR_AUTH_ADMIN instead of BSP application ACO_BSP_ADMIN. To do this, import the Support Package listed in this note then use transaction SICF to activate the service /default_host/sap/bc/webdynpro/sap/CPROJECTS_AUTH_ADMIN. To ensure that the BSP application ACO_BSP_ADMIN can no longer be used, deactivate the service /default_host/sap/bc/bsp/sap/aco_bsp_admin in transaction SICF.

cProjects 3.x
The solution is described in Note 1515424.

Other solution option
Upgrade your system to cProjects 4.0 or a subsequent release or, if you do not use the application, deactivate the BSP application ACO_BSP_ADMIN in transaction SICF:

  • Call transaction SICF.
  • Expand the path: default_host -> sap -> bc -> bsp -> sap.
  • Deactivate the service for ACO_BSP_ADMIN.

CVSS

Score 0

References

Full note on SAP: SAP Support Launchpad note 1229303

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More