SAP Security Note
Medium priority
SAP security note 2022818, "Authorization check for RFC in FS-CML", is a program error note released on 11.11.2014. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Remote Function Calls (RFC) to certain function modules in loans management were previously protected only by the S_RFC authorization checks. It was identified that these checks alone might not ensure secure execution for the affected RFC function modules.
Solution
Implement the new authorization checks as outlined in this SAP Note to ensure secure execution of the affected RFC function modules.
Reason and prerequisites
While many RFC function modules are adequately protected using S_RFC authorization checks, they often lack additional functional authorization safeguards. This SAP Note addresses the insufficiency of S_RFC alone and enhances security by implementing further authorization checks. For more information on RFC security, refer to SAP Note 2008727 – Securing Remote Function Calls (RFC).
References
This note refers to
- SAP Note 2008727 – Securing Remote Function Calls (RFC)
Referenced by
- SAP Note 2061775 – Adjustment CL_RFC / II
- SAP Note 2037292 – Adjustment CL_RFC
Affected components
- EA-FINSERV: 600, 603, 604, 605, 606, 616, 617
Full note on SAP: SAP Support Launchpad note 2022818
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



