Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable authorization checks for RFC in CRM-MW-ADP, SAP security note 2275009

SAP Note 2275009

SAP security note 2275009, "Switchable authorization checks for RFC in CRM-MW-ADP". Below are the symptom, SAP recommended solution and the affected software components.

ComponentCRM-MW-ADP

Description

Symptom

This SAP security note introduces new switchable authorization checks for RFC function modules SMOF_START_DOWNLOAD_OR_REQUEST and SMOF0_INIT_OBJ_SET_DNL_STAT_R within the CRM Middleware Adapter (CRM-MW-ADP). These checks enhance the security by ensuring that remote calls to RFC functions are adequately protected beyond the standard S_RFC authorization object.

Solution

To implement the new authorization checks, apply the provided support packages or correction instructions to pre-implement the checks. The checks will remain inactive post-installation.

  • Step 1: Start transaction SACF in your development system. Verify if the scenario definition MWADP exists. If not, download the attachment MWADP.TXT and upload it via transaction SACF_TRANSFER. Assign the scenario to the development package SMOF.
  • Step 2: Create the productive authorization scenario in SACF. Activate the switchable authorization checks as detailed in SAP Note 1922808.

CVSS

Score 6.3 / 10 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected components

  • CRM-MW-ADP: BBPCRM 600 to 714

Full note on SAP: SAP Support Launchpad note 2275009

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More