Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Blocking unauthorized access to system using TMSADM to 4.6B, SAP security note 1486759

SAP Note 1486759

SAP security note 1486759, "Blocking unauthorized access to system using TMSADM to 4.6B". Below are the symptom and SAP recommended solution.

Description

Symptom

Unauthorized accesses to the system using the user TMSADM are to be prevented. To prevent misuse, the password of the user TMSADM must be changed.

Solution

Make sure that either scenario 1 or 2 applies. Lock the user account TMSADM in the client 000.

After you lock it, the user TMSADM can no longer be used. The system then requests additional logon prompts in the Transport Management System (TMS), for example, when you display the import queue or distribute the configuration.

If the prerequisites (scenario 1 or scenario 2) do not apply, the following errors occur:

  • Function: TMS_CI_CHECK_ACCESSTOKEN
  • Message: RFC_COMMUNICATION_FAILURE
  • Details: RFC communications error with system/destination TMSADM@<sys>.<domain> User is locked. Please notify the person responsible

Reason and prerequisites

A standard password is used. The standard password can be changed only as of Release 4.6C or higher. The following two scenarios are supported:

  • Scenario 1: All systems in the landscape are treated the same with regard to TMSADM.
  • Scenario 2: The system is not the domain controller and the other systems that have not been treated retain the standard password.

If neither of the two scenarios applies, the domains must be reconfigured to establish the prerequisite.

References

Full note on SAP: SAP Support Launchpad note 1486759

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More