Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable authorization checks for RFC in LO, SAP security note 2068606

SAP Note 2068606

SAP security note 2068606, "Switchable Authorization Checks for RFC in LO", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

Authorization object S_RFC may not provide sufficient security for certain RFC function modules in LO. This can potentially allow unauthorized access if S_RFC authorizations are overly broad.

Solution

New switchable authorization checks are delivered inactive to maintain process compatibility. They can be activated in transaction SACF as per the manual correction instructions provided in the note.

  • Scenario definition: ensure scenario definitions exist in SACF; if not, upload the attached scenario definition file for this note.
  • Create productive scenario: transfer the scenario definition to a productive scenario in SACF, setting the status to "Active" or "Logging".
  • Security Audit Log: activate logging of relevant audit messages in the Security Audit Log via transaction SM19.
  • Adjust roles: update user roles to include necessary authorizations based on the new authorization scenario, using report RSAU_SELECT_EVENTS and authorization traces (STAUTHTRACE or ST01).
  • Affected RFC function modules: CRM_BILLING_GET_FI_SD_DOCS, MATERIAL_UPLOAD_GET_DETAIL, CRM_CO_REPORT_SINGLE.
  • New authorization objects: F_BKPF_BLA with activity 03 (Display), F_BKPF_BUK with activity 03 (Display), M_MATE_MAT with activity 03, S_TCODE with transaction code KCRMCO_CSCEN.

References

Full note on SAP: SAP Support Launchpad note 2068606

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More