Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

EP 5.0 SP3 Single Sign-On with User ID/Password to R/3, SAP security note 513864

SAP Note 513864
SAP Security Note
Low priority

SAP security note 513864, "EP 5.0 SP3: Single Sign-On with User ID/Password to R/3", is a consulting note released on 08.10.2009. Below are the symptom, SAP recommended solution and the affected software components.

ComponentEnterprise Portal > SAP Enterprise Portal (On Premise) > Security > SingleSignOn
CategoryConsulting
PriorityCorrection with low priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on08.10.2009
LanguageEnglish

Description

Symptom

You wish to use Single Sign-On with user ID and password to R/3 Systems.

Solution

As of Enterprise Portal 5.0 SP3, you can use Single Sign-On with user ID and password to access the following SAP application types:

  • Transactions using SAP GUI for HTML, SAP GUI for Java, and SAP GUI for Windows
  • Internet Application Components (IACs)
  • MiniApps
  • Business Server Pages (BSPs)
  • BW reports
  • Drag&Relate objects
WarningIn the above cases, the user ID and password are transmitted in plain text in the URL. The URL is requested using the HTTP GET method, so even using HTTPS is not completely safe. The URLs containing the user ID and password in plain text can be logged by the Web server or eavesdropped by an external party.

In general, we recommend using Single Sign-On with SAP logon tickets or client certificates. Single Sign-On with user ID and password should only be used if no other Single Sign-On method is possible. It has the following advantages:

  • It can be used for SSO to SAP Systems that do not support SAP logon tickets (release < 4.0B).
  • You do not have to have Central User Administration in place. Users can have different user IDs in the different systems of the system landscape.

CVSS

Score 0

References

Affected components

  • EP-PSERV: From 5.0 To 5.0

Full note on SAP: SAP Support Launchpad note 513864

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More