SAP Security Note
Low priority
SAP security note 2185122, "Switchable Authorization Checks for RFC in Data Extraction within CA-MDG-APP-FIN", is a program error note released on July 6, 2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This SAP Note introduces new switchable authorization checks for RFC function modules in CA-MDG-APP-FIN, specifically targeting data extraction function modules. The enhancement ensures that remote calls to RFC function modules are protected by additional authorization object checks, thereby strengthening system security.
Solution
New switchable authorization checks have been implemented but remain inactive by default to maintain compatibility with existing processes.
References
- SAP Note 2051936 – SACF_TRANSFER | Download only takes logon language into account
- SAP Note 2008727 – Securing Remote Function Calls (RFC)
- SAP Note 1995667 – SACF: Navigation error
- SAP Note 1989576 – SACF: Incomplete data after import
- SAP Note 1988903 – Check whether a function module was called via external RFC
- SAP Note 1917367 – SACF: Supplementary corrections
- SAP Note 1908870 – SACF | Workbench for switchable authorization scenarios
- SAP Note 1882417 – External check for Remote Function Call
Affected components
- MDG_FND (731 to 800)
- SAP_BASIS (700 to 740, specific support package levels)
Full note on SAP: SAP Support Launchpad note 2185122
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
