SAP security note 2058934, "Switchable Authorization Checks for RFC in LE-WM", is a note. Below is the SAP recommended solution.
Description
Solution
New authorization scenarios, LE_WMS_DEC_CEN_CHECK and LE_WM_IDOCMON_RFC, have been implemented to provide granular authorization checks for RFC function modules in LE-WM (Warehouse Management). The checks are delivered inactive to maintain compatibility and can be activated manually using transaction SACF.
- Upload the scenario definitions via transaction
SACF_TRANSFERand assign them to the development packageLVS. - Convert the scenario definitions into productive authorization scenarios in transaction
SACF, setting the initial status to Active or Logging. - Activate the Security Audit Log via transaction
SM19and configure relevant audit message filters. - Update user roles to include the new authorization objects; use report
RSAU_SELECT_EVENTSto identify users needing additional authorizations.
Full note on SAP: SAP Support Launchpad note 2058934
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



