Skip to Content
Author's profile photo Former Member

PI 7.31 : Java properties comparision. A security Hole?

Most of you are aware of the new feature called : Compare systems in PI 7.31 which helps to identify the differences between the systems + various system properties. I just love this feature 🙂

But you could easily get the passwords of all PI service users such as PIISXXX, PIDIRXXX, PIREPXXX etc.

The comparison result listed the passwords in free text 🙁

/wp-content/uploads/2013/02/22_02_01_188263.jpg

/wp-content/uploads/2013/02/22_02_02_188267.jpg

/wp-content/uploads/2013/02/22_02_03_188268.jpg

/wp-content/uploads/2013/02/22_02_04_188269.jpg

Even though the user has J2EE_ADMIN rights, he/she should not be able to see any system passwords . Please correct me if I am wrong.

Probably something for SAP to fix ???

Share your thoughts

Assigned Tags

      Be the first to leave a comment
      You must be Logged on to comment or reply to a post.