SAP Security Note
Medium priority
SAP security note 1302928, “Field Level Authorizations Not Being Checked in CASE”, is a program error note released on 08.10.2009. Below are the symptom, SAP recommended solution, reason and prerequisites and the affected software components.
Description
Symptom
User has assigned the authorization at field level, i.e., for Attributes. User can set ‘Display Only’ property for the attribute in two ways:
1. The authorization assigned by the user is ‘Display only’. Even though the user has assigned Display Authorization for attributes, the user was still able to change the values for the Fields having F4 helps.
2. The user makes the field ‘Not Modifiable’ from customizing, then also the user is able to make changes to the fields having F4 help assigned.
Solution
Apply the note.
Reason and prerequisites
No check was done for ‘Non Modifiable’ attributes with F4 help assigned before displaying, and the value for fields having F4 help assigned are sent to the screen.
References
- SAP Note 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- SAP_BASIS 6.40 to 6.40
- SAP_BASIS 7.00 to 7.01
- SAP_BASIS 7.10 to 7.11
Full note on SAP: SAP Support Launchpad note 1302928
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
