SAP Security Note
Medium priority
SAP security note 2181460, "Unauthorized usage of application functionality in SAP Exchange Infrastructure", is a program error note released on 13.09.2016. Below are the symptom, SAP recommended solution and reason and prerequisites.
Description
Symptom
An attacker can remotely exploit Integration Builder Directory, potentially consuming resources used to serve PI. Additionally, a security fix may cause cache refresh issues, resulting in the following error in sxi_cache:
"Error ‘HTTP status code 403 Forbidden’ while executing HTTP request (calling method ‘get_status’)"
Solution
Implement the correction instructions by following the manual steps outlined in Manual Activities or by importing the relevant support package. After applying the fix, the ABAP consumer system will retrieve the updated content successfully.
Reason and prerequisites
Usage: the system uses SAP Exchange Infrastructure as the central Integration Server or as the local Integration Engine in an application system.
Issue: the ABAP client accesses the Integration Builder Directory to perform cache refresh. The error occurs due to XSRF protection being enabled.
Full note on SAP: SAP Support Launchpad note 2181460
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
