Symptom
While performing a security scan against an SAP system, the security tools logs the vulnerability "SAP Message Server Endpoints Accessible".
A sample output can be:
SAP Message Server Endpoint msgserver detected on port [Message Server HTTP port].
SAP Message Server Endpoint msgserver/commands detected on port [Message Server HTTP port]
SAP Message Server Endpoint msgserver/html/aslist detected on port [Message Server HTTP port]
SAP Message Server Endpoint msgserver/xml/aslist detected on port [Message Server HTTP port]
SAP Message Server Endpoint msgserver/text/aslist detected on port [Message Server HTTP port]
SAP Message Server Endpoint msgserver/html/lglist detected on port [Message Server HTTP port]
SAP Message Server Endpoint msgserver/xml/lglist detected on port [Message Server HTTP port]
SAP Message Server Endpoint msgserver/text/lglist detected on port [Message Server HTTP port]
SAP Message Server Endpoint msgserver/html/logon detected on port [Message Server HTTP port]
SAP Message Server Endpoint msgserver/xml/logon detected on port [Message Server HTTP port]
SAP Message Server Endpoint msgserver/text/logon detected on port [Message Server HTTP port]
Read more...
Environment
- SAP NetWeaver based product
- ABAP Platform based product
Product
Keywords
KBA , BC-CST-MS , Message Service , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview