Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Authorization check for RFC in FS-CML, SAP security note 2022818

SAP Note 2022818
SAP Security Note
Medium priority

SAP security note 2022818, "Authorization check for RFC in FS-CML", is a program error note released on 11.11.2014. Below are the symptom, SAP recommended solution and the affected software components.

ComponentFS-CML (Financial Services > Consumer and Mortgage Loans)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on11.11.2014
LanguageEnglish

Description

Symptom

Remote Function Calls (RFC) to certain function modules in loans management were previously protected only by the S_RFC authorization checks. It was identified that these checks alone might not ensure secure execution for the affected RFC function modules.

Solution

Implement the new authorization checks as outlined in this SAP Note to ensure secure execution of the affected RFC function modules.

Reason and prerequisites

While many RFC function modules are adequately protected using S_RFC authorization checks, they often lack additional functional authorization safeguards. This SAP Note addresses the insufficiency of S_RFC alone and enhances security by implementing further authorization checks. For more information on RFC security, refer to SAP Note 2008727 – Securing Remote Function Calls (RFC).

References

This note refers to

Referenced by

Affected components

  • EA-FINSERV: 600, 603, 604, 605, 606, 616, 617

Full note on SAP: SAP Support Launchpad note 2022818

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More