SAP Knowledge Base Article - Preview

3382611 - 500 Internal Server Error for users with only monitoring roles assigned after SP upgrade

Symptom

  • You upgraded the PO system to SP 25 or higher.
  • Post upgrade, users assigned with only monitoring roles are getting "500 Internal Server Error" while trying to access the message monitor.
  • Default trace shows the below logs:

    500 Internal Server Error is returned for HTTP request:
      component [dispatcher],
      web module [webdynpro/resources/sap.com/tc~lm~itsam~ui~mainframe~wd],
      application [sap.com/tc~lm~itsam~ui~mainframe~wd],
      DC name [sap.com/tc~lm~itsam~ui~mainframe~wd],
      CSN component[BC-NWA-INC-UIF],
      problem categorization [],
      internal categorization [-1073149452].

    [EXCEPTION]
    java.lang.SecurityException: User XXXXX is not authorized.
        at com.sap.engine.interfaces.security.SecurityThreadContext.checkAuthorized(SecurityThreadContext.java:159)
        at com.sap.engine.interfaces.security.SecurityThreadContext.checkAuthorized(SecurityThreadContext.java:132)
        at com.sap.aii.af.util.AuthorizationChecker.checkAuthorization(AuthorizationChecker.java:28)


Read more...

Environment

SAP Process Integration

SAP Process Orchestration

Keywords

500 Internal Server Error, java.lang.SecurityException: User XXXXX is not authorized, Message Monitor, CVE-2022-41271, CVE-2022-41272, roles. , KBA , BC-NWA-XPI , Process Integration (PI) Monitoring , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.