Support Note KB0394017
Email
Why was my session terminated for security reasons? (IP address discrepancy)
Symptom

Why am I being logged out of the Ariba system with the following security warning error message:

Ariba had to terminate your current session for security reasons because we have identified a discrepancy in your current IP address from the IP address used in previous requests. Please return to the Ariba Login page and log in again to reset your session credentials.


Environment

Ariba on-demand solutions


Reproducing the Issue

The issue can occur when you perform an action in the Ariba application after:


Cause

This session termination is a security feature designed to protect your account from unauthorized access (hacking) and fraud.

Ariba checks your Internet Protocol (IP) address with every request you make (like clicking a button or opening a document). If your current IP address is significantly different from the one used in the previous request, the system terminates the session as a precaution.

This IP address change is often caused by:


Resolution

There are two possible solutions to prevent this issue:

Solution 1: Use a Static IP and Add Ariba to Trusted Sites (All Users)

  1. Work with your IT department to obtain a static IP address for the machine you use to connect to Ariba.
  2. Add the Ariba URL to your browser's list of trusted sites to ensure a stable connection.

To add Ariba to trusted sites in Windows:

  1. Open Control Panel.
  2. Choose Internet Options.
  3. Access the Security tab.
  4. Click the Trusted Sites icon.
  5. Click the Sites button.
  6. Ensure the box beside Require server verification (https:) for all sites in this zone is unchecked.
  7. Enter *.ariba.com in the Add this website to the zone field.
  8. Click Add > Close > OK.


Solution 2: Request a Change to Remote Host Checking (Buyers Only)

If you are a Buyer, your designated account administrator can submit a Case to SAP Support to request a change to the Remote Host Checking settings for your company's site. Provide one of the following options in your request:

Option A: Define Trusted IP Addresses: Provide SAP Support with a set of approved IP address ranges for your organization. If a user's IP address changes to another address within this trusted list, their session will not be terminated. You will need to get these valid IP ranges from your IT team.
Option B: Disable Remote Host Checking: Request to have the IP address check disabled entirely for your site. This reduces security but prevents session termination from IP changes.



Applies To

Catalog Management
Core Procurement > Core Administration > Core Administration User Management
Invoicing
Procurement Core Platform > Encryption, Key Management Service, GBaaS,File Fortification
SAP Business Network for Procurement & Supply Chain
SAP Business Network for Procurement & Supply Chain > Discovery & Sourcing/Contract Punchout Scenario
Spend Visibility
Strategic Contracts
Strategic Sourcing
Supplier Information & Performance Management

Terms of Use  |  Copyright  |  Security Disclosure  |  Privacy