SAP Security Note
High priority
SAP security note 1562545, "Display user in FS-PMA", is a program error note released on 08.03.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
In FS-PM Auto, the authorizations for some transactions cannot be restricted to "read" only. As a result, each user who is authorized to execute the transactions automatically receives the right to make changes.
Some transactions are not secured using authorization objects, preventing restriction of execution authorization. If a user knows the transaction codes, they can change data without proper authorization.
There are unsecured obsolete transactions in the system, allowing users to enter inconsistent data if they know the transaction codes.
Solution
To correct the problem, implement the source code corrections and perform the following manual tasks. Support Package SAPK-11001INFSPMAUTO corrects the problem.
Reason and prerequisites
The authorization objects of the affected transactions do not allow users to explicitly request change rights.
Missing authorization objects cause the inability to restrict execution authorization.
Obsolete transactions remain unsecured in the system.
Full note on SAP: SAP Support Launchpad note 1562545
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
