Symptom
While performing a security scan against an SAP system, the security tools logs the vulnerability "SAP Message Server Endpoints Accessible".
A sample output can be:
SAP Message Server Endpoint msgserver detected on port [Message Server HTTP port].
SAP Message Server Endpoint msgserver/commands detected on port [Message Server HTTP port]
SAP Message Server Endpoint msgserver/html/aslist detected on port [Message Server HTTP port]
SAP Message Server Endpoint msgserver/xml/aslist detected on port [Message Server HTTP port]
SAP Message Server Endpoint msgserver/text/aslist detected on port [Message Server HTTP port]
SAP Message Server Endpoint msgserver/html/lglist detected on port [Message Server HTTP port]
SAP Message Server Endpoint msgserver/xml/lglist detected on port [Message Server HTTP port]
SAP Message Server Endpoint msgserver/text/lglist detected on port [Message Server HTTP port]
SAP Message Server Endpoint msgserver/html/logon detected on port [Message Server HTTP port]
SAP Message Server Endpoint msgserver/xml/logon detected on port [Message Server HTTP port]
SAP Message Server Endpoint msgserver/text/logon detected on port [Message Server HTTP port]
Read more...
Environment
- SAP NetWeaver based product
- ABAP Platform based product
Product
Keywords
KBA , BC-CST-MS , Message Service , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.