SAP security note 2517501, "Switchable Authorization Checks for SAP ERP Funds Management Account Assignments". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Authorization checks in certain Funds Management Account Assignments within SAP ERP may be insufficient, potentially allowing unauthorized access to sensitive functions.
Authorization checks do not adequately secure the execution of function modules related to Funds Management Account Assignments in transactions FP04 (Write-Off Items) and FMCAALOT (Approve Write-Off).
Solution
Implement the new switchable authorization checks provided by this SAP Note. The checks are delivered inactive by default to maintain compatibility with existing processes and can be activated manually.
- Activate Authorization Checks: Use transaction SACF to activate the switchable authorization checks as detailed in the SAP Note. Follow the manual activities outlined in the Correction Instructions section of the note.
- Adjust User Roles: Ensure that user roles are updated to accommodate the new authorization scenarios using transactions STAUTHTRACE or ST01 for authorization analysis.
CVSS
Score 6.3/10 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
References
- Reference SAP Note 1922808: Provides more details on the switchable authorization check framework (SACF). View Note
Affected components
- FI-CA: Versions 600 to 801
- IS-PS-CA: Versions 600 to 802
- S4CORE: Version 102
- SAPSCORE: Version 111
Full note on SAP: SAP Support Launchpad note 2517501
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
