SAP security note 2068606, "Switchable Authorization Checks for RFC in LO", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
Authorization object S_RFC may not provide sufficient security for certain RFC function modules in LO. This can potentially allow unauthorized access if S_RFC authorizations are overly broad.
Solution
New switchable authorization checks are delivered inactive to maintain process compatibility. They can be activated in transaction SACF as per the manual correction instructions provided in the note.
- Scenario definition: ensure scenario definitions exist in SACF; if not, upload the attached scenario definition file for this note.
- Create productive scenario: transfer the scenario definition to a productive scenario in SACF, setting the status to "Active" or "Logging".
- Security Audit Log: activate logging of relevant audit messages in the Security Audit Log via transaction
SM19. - Adjust roles: update user roles to include necessary authorizations based on the new authorization scenario, using report
RSAU_SELECT_EVENTSand authorization traces (STAUTHTRACEorST01). - Affected RFC function modules:
CRM_BILLING_GET_FI_SD_DOCS,MATERIAL_UPLOAD_GET_DETAIL,CRM_CO_REPORT_SINGLE. - New authorization objects:
F_BKPF_BLAwith activity 03 (Display),F_BKPF_BUKwith activity 03 (Display),M_MATE_MATwith activity 03,S_TCODEwith transaction codeKCRMCO_CSCEN.
References
- 2078596 – Further improvements for RFC security
- 2023449 – Switchable authorization checks for RFC in FI, FI-AP-AP, FI-AR-AR, FI-BL-MD-BK
- 1906927 – Missing authorization check in Accounting BAPIs
Full note on SAP: SAP Support Launchpad note 2068606
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
