Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable authorization checks for RFC in CRM-MW-CCO, SAP security note 2266040

SAP Note 2266040

SAP security note 2266040, "Switchable Authorization Checks for RFC in CRM-MW-CCO". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Remote calls to RFC function modules are currently protected by checks on the authorization object S_RFC. However, these checks alone may not be sufficient for all RFC function modules, potentially allowing unauthorized access.

Solution

Activate the new switchable authorization checks and update the corresponding roles if the affected RFC function modules are included in your S_RFC authorizations. Use transaction SACF to create and activate the authorization scenario CRM_MW_MOB, choosing between Active or Logging status based on your requirements. Identify and update user roles to include the necessary authorizations for the new scenario.

References

Affected components

  • BBPCRM, valid from release 700 to 715+

Full note on SAP: SAP Support Launchpad note 2266040

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More