SAP Security Note
High priority
SAP security note 1418848, "Authorization check for S_RFC_ADM in RSRFCPIN and RSRFCCHK", is a program error note released on 11.05.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
During an RFC ping, the authorization check in the target system is not protected by a check with the authorization object S_RFC_ADM if it is called from the report RSRFCPIN or the report RSRFCCHK.
Solution
Import the relevant Support Package or implement the correction instructions. After implementing these corrections, RFC pings with a check of the logon data in the target system are protected by an authorization check with the authorization object S_RFC_ADM.
Reason and prerequisites
This problem is caused by a missing authorization check using S_RFC_ADM if the report RSRFCPIN is called with the "Authorization Check" input parameter or if the report RSRFCCHK is called.
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1418848
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




