Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Authorization checks for RFC in E-Recruiting, SAP security note 2059230

SAP Note 2059230
Medium priority

SAP security note 2059230, "Authorization checks for RFC in E-Recruiting", is a note released on November 11, 2014. Below are the symptom, SAP recommended solution and the affected software components.

ComponentPersonnel Management > E-Recruiting (PA-ER)
PriorityCorrection with medium priority
Released onNovember 11, 2014

Description

Symptom

Remote calls to RFC function modules were previously protected by the authorization object S_RFC. However, it was identified that these checks might not suffice to ensure secure execution for certain RFC function modules within E-Recruiting.

Solution

The security note implements additional authorization checks using existing authorization objects. Administrators should apply the attached correction instructions to ensure that authorizations for S_RFC are limited to the minimum necessary for all users. The affected RFC function module is HRRCF_MDL_ADMN_CHECK_EXT_CAND.

References

Affected components

  • PA-ER (versions 600, 603, 604, 605, 606, 616, 617, 800, 801, 802)

Full note on SAP: SAP Support Launchpad note 2059230

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More