<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SAPXPG vulnerability in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/sapxpg-vulnerability/m-p/4329500#M1031602</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are concerned about a vulnerability of of using  SAPXPG to issues OS commands to shutdown or otherwise tamper with the availability of the SAP system. Please advise of how to close this vulnerability.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Aug 2008 19:22:28 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2008-08-20T19:22:28Z</dc:date>
    <item>
      <title>SAPXPG vulnerability</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sapxpg-vulnerability/m-p/4329500#M1031602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are concerned about a vulnerability of of using  SAPXPG to issues OS commands to shutdown or otherwise tamper with the availability of the SAP system. Please advise of how to close this vulnerability.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Aug 2008 19:22:28 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sapxpg-vulnerability/m-p/4329500#M1031602</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-08-20T19:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: SAPXPG vulnerability</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sapxpg-vulnerability/m-p/4329501#M1031603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAPXPG is really only ment to be used internally. As the ABAP system is platform independent it makes use of external RFC servers &lt;STRONG&gt;started&lt;/STRONG&gt; by SAP Gateway to perform platform dependent tasks. One example is executing operating system commands using transaction SM49. There is no SAP standard scenario that would remotely require the SAP Gateway to &lt;STRONG&gt;start&lt;/STRONG&gt; any of these external RFC servers. You can therefore restrict access as documented in [Security Settings in SAP Gateway|http://help.sap.com/saphelp_nw70/helpdata/EN/1c/468e2f161b4f96b5401f02d30943b1/frameset.htm] to local access only. Remote access is only required for remote &lt;STRONG&gt;registration&lt;/STRONG&gt; of RFC servers. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example configurations:&lt;/P&gt;&lt;P&gt;secinfo (control access to RFC servers &lt;STRONG&gt;started&lt;/STRONG&gt; by SAP Gateway):&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;# allow only local calls from ABAP to RFC servers on the local application server itself:
USER=*, USER-HOST=local, HOST=local, TP=*;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;reginfo (control access to and from RFC servers &lt;STRONG&gt;registered&lt;/STRONG&gt; by SAP Gateway):&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;# allow remote registration of RFC servers (TREX, IGS, etc.)
# check logged on clients in transaction SMGW to get a specific list of registered RFC servers on your system
TP=*&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please also have a look at the documentation above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Aug 2008 20:52:16 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sapxpg-vulnerability/m-p/4329501#M1031603</guid>
      <dc:creator>christian_wippermann</dc:creator>
      <dc:date>2008-08-20T20:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: SAPXPG vulnerability</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sapxpg-vulnerability/m-p/4329502#M1031604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the input! Really appreciated!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Sep 2008 15:21:27 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sapxpg-vulnerability/m-p/4329502#M1031604</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-04T15:21:27Z</dc:date>
    </item>
  </channel>
</rss>

