Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in VIRSA and VIRSANH, SAP security note 1690942

SAP Note 1690942
High priority

SAP security note 1690942, "Missing Authorization Check in VIRSA and VIRSANH", is a note released on 12.06.2012. Below are the symptom and SAP recommended solution.

ComponentGRC-SAC-EAM
PriorityCorrection with high priority
StatusReleased for Customer
Released on12.06.2012

Description

Symptom

An authenticated user can use functions of VIRSA and VIRSANH to which access should be restricted. This may result in an escalation of privileges.

Solution

In the GRC SPM application, the user exit SUSR0001 has been used to prevent the direct login of Fire Fighter IDs into the R/3 application. The include /virsa/zvirsa_userexit manages the prevention of FFIDs from direct login. However, this user exit can be bypassed.

To overcome this security gap, a Trusted RFC concept has been implemented in the SPM application. Benefits of Trusted RFC include that passwords are not required for logging in via RFC when an FFID logs into the system.

For trusted RFC settings, additional authorization details, and Fire Fighter Role modifications, please refer to the attachment.

Reason and prerequisites

VIRSA and VIRSANH do not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This may result in undesired system behavior.

References

Full note on SAP: SAP Support Launchpad note 1690942

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More