Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Field Level Authorizations Not Being Checked in CASE, SAP security note 1302928

SAP Note 1302928
SAP Security Note
Medium priority

SAP security note 1302928, “Field Level Authorizations Not Being Checked in CASE”, is a program error note released on 08.10.2009. Below are the symptom, SAP recommended solution, reason and prerequisites and the affected software components.

ComponentBasis Components > Basis Services/Communication Interfaces > Case Management
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on08.10.2009
LanguageEnglish

Description

Symptom

User has assigned the authorization at field level, i.e., for Attributes. User can set ‘Display Only’ property for the attribute in two ways:

1. The authorization assigned by the user is ‘Display only’. Even though the user has assigned Display Authorization for attributes, the user was still able to change the values for the Fields having F4 helps.

2. The user makes the field ‘Not Modifiable’ from customizing, then also the user is able to make changes to the fields having F4 help assigned.

Solution

Apply the note.

Reason and prerequisites

No check was done for ‘Non Modifiable’ attributes with F4 help assigned before displaying, and the value for fields having F4 help assigned are sent to the screen.

References

  • SAP Note 888889 – Automatic checks for security notes using RSECNOTE (outdated)

Affected components

  • SAP_BASIS 6.40 to 6.40
  • SAP_BASIS 7.00 to 7.01
  • SAP_BASIS 7.10 to 7.11

Full note on SAP: SAP Support Launchpad note 1302928

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More