SAP Security Note
High priority
SAP security note 1229303, "Security gap in ACO_BSP_ADMIN", released on 03.02.2011. Below are the symptom and the SAP recommended solution.
Description
Symptom
In BSP application ACO_BSP_ADMIN you can change the search help URL to any search help that exists in the system.
Solution
cProjects 4.0
Use Web Dynpro application DPR_AUTH_ADMIN instead of BSP application ACO_BSP_ADMIN. To do this, import the Support Package listed in this note then use transaction SICF to activate the service /default_host/sap/bc/webdynpro/sap/CPROJECTS_AUTH_ADMIN. To ensure that the BSP application ACO_BSP_ADMIN can no longer be used, deactivate the service /default_host/sap/bc/bsp/sap/aco_bsp_admin in transaction SICF.
cProjects 3.x
The solution is described in Note 1515424.
Other solution option
Upgrade your system to cProjects 4.0 or a subsequent release or, if you do not use the application, deactivate the BSP application ACO_BSP_ADMIN in transaction SICF:
- Call transaction SICF.
- Expand the path: default_host -> sap -> bc -> bsp -> sap.
- Deactivate the service for ACO_BSP_ADMIN.
CVSS
Score 0
References
- 1515424: Security Note: Security gap in ACO_BSP_ADMIN II
- 888889: Automatic checks for security notes using RSECNOTE (outdated)
Full note on SAP: SAP Support Launchpad note 1229303
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



