SAP Security Note
SAP security note 2268252, "Switchable authorization checks for RFC in CRM-MW-GWI-GWA", is released on October 11, 2016. Below are the symptom and SAP recommended solution.
Description
Symptom
This SAP note introduces new switchable authorization checks for RFC function modules in CRM-MW-GWI-GWA. Remote calls to RFC function modules are now protected by enhanced checks on the authorization object S_RFC. These checks help ensure that authorizations are limited to the necessary minimum, thereby enhancing system security. If your system includes the RFC function modules covered by this note, it is crucial to activate these new authorization checks and update the corresponding roles.
Solution
New switchable authorization checks have been implemented and are delivered inactive to maintain compatibility with existing processes.
- Affected RFC function module ISP_CRMMB_OUTBOUND, authorization object CRM_MW_GA, ACTVT=16
- Affected RFC function module ISP_INBOUND, authorization object CRM_MW_GA, ACTVT=16
- Affected RFC function module ISP_MAPBOX_CALL, authorization object CRM_MW_GA, ACTVT=16
- Affected RFC function module ISP_XML_OUTBOUND, authorization object CRM_MW_GA, ACTVT=16
- Affected RFC function module ISP_XML_INBOUND, authorization object CRM_MW_GA, ACTVT=16
- Create the authorization scenario definition in transaction SACF (upload the CRM_MW_GW_GWA.TXT file via SACF_TRANSFER if the scenario CRM_MW_GW_GWA does not exist)
- Transfer the scenario definition to a productive scenario in SACF and set its status to Active or Logging
- Activate logging of SACF-relevant audit messages in the Security Audit Log via transaction SM19
- Adjust roles to provide the necessary authorizations, using report RSAU_SELECT_EVENTS
Full note on SAP: SAP Support Launchpad note 2268252
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




