SAP Knowledge Base Article - Preview

3786599 - IP Whitelisting Bypass via Spoofable Headers and Recommended Secure Configuration Using Access Control Policy in SAP API Management

Symptom

 One or more of the following situations is observed in SAP API Management:

  - The Access Control policy is configured to allow only specific IP addresses, but requests from non-whitelisted IPs are still reaching the proxy when the caller sets an allowed IP address in the
  X-Forwarded-For or True-Client-IP request header.
  - A custom IP whitelisting solution is implemented using KeyValueMapOperations, JavaScript, and RaiseFault policies, but the validation can be bypassed because all available header values (X-Forwarded-For, True-Client-IP, client.ip) are either spoofable by the client or resolve to an internal load balancer IP.
  - The Apigee variable client.resolved.ip is referenced in documentation or community content, but it is not available in SAP API Management and returns no value.


Read more...

Environment

  • SAP Integration Suite
  • API Management

Product

API Management all versions

Keywords

 ACCESS CONTROL, IP WHITELISTING, IP BYPASS, X-FORWARDED-FOR, TRUE-CLIENT-IP, VALIDATEBASEDON, IGNORETRUECLIENTIPHEADER, X_FORWARDED_FOR_LAST_IP, CLIENT.IP, CLIENT.RESOLVED.IP, SPOOFABLE HEADER, API PROXY, APIGEE, GEO-FENCING, API Management, SAP API Management, APIM, SAP Integration Suite, API Proxy, API Provider, Policy, Apigee

, KBA , OPU-API-OD-DT , Designtime , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.