SAP Security Note
Medium priority
SAP security note 2264976, "CRM_Switchable authorization checks for RFC in CRM-MW-BDM", is a program error note released on 13.11.2017. Below are the symptom and SAP recommended solution.
Description
Symptom
Securitization of RFC function modules in CRM-MW-BDM was identified as insufficient. The note introduces switchable authorization checks to ensure enhanced security measures.
Solution
New switchable authorization checks are delivered inactive to maintain compatibility. They can be activated via transaction SACF following the manual correction instructions provided in the note.
- Transaction SACF: Verify or create the authorization scenario CRM_MW_GWMOB.
- Create Productive Scenario: Transfer the scenario definition to a productive scenario and set its status to "Active" or "Logging".
- Activate Logging: Ensure Security Audit Log is activated in transaction SM19 and configure relevant message IDs (DUO, DUP, DUQ).
- Adjust Roles: Modify user roles to include the necessary authorizations identified by the new scenario.
Reason and prerequisites
Implementation of SAP Note 2266982 is required before applying this note. The existing authorization object S_RFC needed additional checks to secure RFC function modules effectively.
Full note on SAP: SAP Support Launchpad note 2264976
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
