SAP Security Note
Low priority
SAP security note 1494606, "Invalid SU22 delivered proposal", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
In transaction SU22, the proposal for object S_TCODE for the transaction PIQAGR_CUST is incorrect.
Solution
Please perform the following steps to prevent this security error:
- Go to transaction SU22.
- Select the following from the initial selection screen: Type of Application: Transaction; Transaction code: PIQAGR_CUST.
- Press the Execute button or hit the F8 key.
- A list of authorization objects will appear. Switch to change mode.
- Select the object S_TCODE and in the Proposal column, change the value to NO.
- Press Save.
This will remove the invalid proposal and ensure that no authorization defaults are maintained for the transaction.
Reason and prerequisites
The proposal status for the authorization object defined for the transaction PIQAGR_CUST was incorrect. An authorization default value for the object was added in the profile generator which was not recommended.
Affected components
- IS-PS-CA 600
- IS-PS-CA 602
- IS-PS-CA 603
- IS-PS-CA 604
- IS-PS-CA 605
Full note on SAP: SAP Support Launchpad note 1494606
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
