Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable authorization checks for RFC in Material Version, SAP security note 2030357

SAP Note 2030357SAP Security NoteMedium priority

SAP security note 2030357, “Switchable authorization checks for RFC in Material Version”, is a program error note released on 10.11.2014. Below is the security information published by SAP for this note.

ComponentIS-A-LMN (Industry-Specific Components > Automotive > Long Material Number)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on10.11.2014
LanguageEnglish

Description

Symptom

This SAP note introduces new switchable authorization checks for RFC function modules in Material Version.

Reason and prerequisites

Remote calls to RFC function modules are currently protected by the authorization object S_RFC. However, S_RFC alone may not sufficiently secure certain RFC function modules. This note addresses these gaps by activating new switchable authorization checks. It is essential to update corresponding roles if these RFC function modules are included in your S_RFC authorizations to ensure system security.

## Solution

New switchable authorization checks have been implemented and are delivered in an inactive state to maintain compatibility with existing processes. These checks can be activated using transaction SACF as outlined in the manual correction instructions.

Full note on SAP: SAP Support Launchpad note 2030357

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More