SAP security note 2273147, "Switchable authorization checks for RFC in CRM-IT-BTX". Below are the symptom, reason and prerequisites and SAP recommended solution.
Description
Symptom
This SAP note describes new switchable authorization checks for RFC function modules in Provider Sales and Order Management – Business Transaction.
Solution
New authorization checks (both switchable and non-switchable) have been implemented. Switchable checks are delivered inactive to ensure compatibility with existing processes and can be activated in transaction SACF as described in the attached manual correction instruction. See SAP Note 1922808 for additional information on the switchable authorization check framework (SACF).
New authorization scenario CRM_ISX_BTX_PROV – Provider Contract RFC authority, used during contract distribution and sending of alerts for prepaid accounts. Affected business processes and roles: Provider Sales and Order Management. Affected RFC function modules:
CRM_ISX_PPACC_ALERT_HANDLER– Auth. ObjectB_BUPA_GRP,B_BUPA_RLT; Parameters ACTVT=03CRM_PROD_UPS_MAINTAIN_2_OW– Auth. ObjectCRM_ORD_PR; Parameters PR_TYPE=Process Type, ACTVT=03
To activate the switchable authorization check: start transaction SACF_TRANSFER, select Upload and choose Scenario Definition, upload the scenario definition file, and assign the scenario to the development package CRM_ISX_BTX_API. In transaction SACF, create the productive authorization scenario and activate the switchable authorization checks as per SAP Note 1922808.
Reason and prerequisites
Remote calls to RFC function modules are protected by checks on the authorization object S_RFC. Authorizations for S_RFC must be limited to the required minimum to ensure system security. Many RFC function modules can be sufficiently protected using S_RFC authorization checks, often without additional functional authorization checks.
It was identified that S_RFC authorization checks might not be sufficient to ensure secure execution for RFC function modules covered by this note. Activate new switchable authorization checks and update corresponding roles if these RFC function modules are included in S_RFC authorizations in your system.
References
Full note on SAP: SAP Support Launchpad note 2273147
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
