SAP Security Note
Medium priority
SAP security note 2417355, "Missing Authorization check in RFC Destination Maintenance", is a program error note released on 2017.04.11. Below are the symptom and SAP recommended solution.
Description
Symptom
RFC Destination Maintenance does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of Missing Authorization check are:
- Abuse functionality restricted to a particular user group
- Read, modify, or delete restricted data
Solution
The correction provided in this note overcomes the gap and extends the authorization check S_RFC_ADM for the field ICF_VALUE.
Please implement the Support Package mentioned in this SAP Note, or apply the respective correction instructions. You can download the necessary support packages and find more information here.
Reason and prerequisites
A user with correct permission to access RFC Destination Maintenance (SM59) is required.
In cases where the user is restricted to editing only some of the RFC Destinations by additional authorization values, the user may overcome this restriction by navigating inside SM59. This will enable the user to maintain RFC Destinations not authorized for.
CVSS
Score 4.70 Vector: NLHN | U | LLL (CVSS v3.0)
Full note on SAP: SAP Support Launchpad note 2417355
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
