Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable authorization checks for RFC in CRM-MW-ADM, SAP security note 2261768

SAP Note 2261768

SAP security note 2261768, “Switchable authorization checks for RFC in CRM-MW-ADM”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

This SAP Security Note introduces new switchable authorization checks for RFC function modules in the CRM Middleware Admin Console. The purpose is to enhance system security by ensuring that remote calls to RFC function modules are protected with the appropriate authorization objects.

Solution

1. Implementation of Switchable Authorization Checks:

  • New authorization checks are delivered inactive to maintain compatibility.
  • Activate these checks in transaction SACF following the manual correction instructions provided.

2. Activation Steps:

  • Step 1: Create the authorization scenario definition in older support packages. Use transaction SACF to check for the scenario CRM_MW_ADM_CONSOLE. If not present, apply Note 2261768 via SNOTE and run the Report Note_2261768 in transaction SE38.
  • Step 2: Create the productive authorization scenario from the scenario definition. In SACF, select the scenario and transfer it to a productive scenario. Choose the initial scenario status (Active or Logging).
  • Step 3: Activate logging of relevant audit messages in the Security Audit Log. Ensure Security Audit Log is activated in transaction SM19. Activate message IDs DUO, DUP, and DUQ.
  • Step 4: Adjust roles to provide necessary authorizations based on the new scenario. Use report RSAU_SELECT_EVENTS to identify users needing authorization adjustments.

Reason and prerequisites

Remote calls to RFC function modules require checks on the authorization object S_RFC. While many RFC function modules can be adequately protected using S_RFC authorizations, some may require additional functional authorization checks to ensure secure execution. This note addresses those scenarios by activating new switchable authorization checks.

References

Affected components

  • BBPCRM 700 to 714

Full note on SAP: SAP Support Launchpad note 2261768

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More