Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CRM_Switchable authorization checks for RFC in CRM-MW-BDM, SAP security note 2264976

SAP Note 2264976
SAP Security Note
Medium priority

SAP security note 2264976, "CRM_Switchable authorization checks for RFC in CRM-MW-BDM", is a program error note released on 13.11.2017. Below are the symptom and SAP recommended solution.

ComponentCRM-MW-BDM
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on13.11.2017

Description

Symptom

Securitization of RFC function modules in CRM-MW-BDM was identified as insufficient. The note introduces switchable authorization checks to ensure enhanced security measures.

Solution

New switchable authorization checks are delivered inactive to maintain compatibility. They can be activated via transaction SACF following the manual correction instructions provided in the note.

  • Transaction SACF: Verify or create the authorization scenario CRM_MW_GWMOB.
  • Create Productive Scenario: Transfer the scenario definition to a productive scenario and set its status to "Active" or "Logging".
  • Activate Logging: Ensure Security Audit Log is activated in transaction SM19 and configure relevant message IDs (DUO, DUP, DUQ).
  • Adjust Roles: Modify user roles to include the necessary authorizations identified by the new scenario.

Reason and prerequisites

Implementation of SAP Note 2266982 is required before applying this note. The existing authorization object S_RFC needed additional checks to secure RFC function modules effectively.

Full note on SAP: SAP Support Launchpad note 2264976

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More