Symptom
- You upgraded the PO system to SP 25 or higher.
- Post upgrade, users assigned with only monitoring roles are getting "500 Internal Server Error" while trying to access the message monitor.
- Default trace shows the below logs:
500 Internal Server Error is returned for HTTP request:
component [dispatcher],
web module [webdynpro/resources/sap.com/tc~lm~itsam~ui~mainframe~wd],
application [sap.com/tc~lm~itsam~ui~mainframe~wd],
DC name [sap.com/tc~lm~itsam~ui~mainframe~wd],
CSN component[BC-NWA-INC-UIF],
problem categorization [],
internal categorization [-1073149452].[EXCEPTION]
java.lang.SecurityException: User XXXXX is not authorized.
at com.sap.engine.interfaces.security.SecurityThreadContext.checkAuthorized(SecurityThreadContext.java:159)
at com.sap.engine.interfaces.security.SecurityThreadContext.checkAuthorized(SecurityThreadContext.java:132)
at com.sap.aii.af.util.AuthorizationChecker.checkAuthorization(AuthorizationChecker.java:28)
Read more...
Environment
SAP Process Integration
SAP Process Orchestration
Keywords
500 Internal Server Error, java.lang.SecurityException: User XXXXX is not authorized, Message Monitor, CVE-2022-41271, CVE-2022-41272, roles. , KBA , BC-NWA-XPI , Process Integration (PI) Monitoring , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.