SAP Security Note
Medium priority
SAP security note 2495144, “Switchable Authorization checks for RFC in Central Finance”, is a program error note released on April 14, 2020. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 2495144 introduces switchable authorization checks for RFC function modules in the source part of Central Finance. This enhancement ensures more granular security by leveraging the new authorization object F_CFIN_SRC, which can be controlled via the scenario FIN_CFIN_SOURCE.
This note addresses the need for enhanced security in Central Finance by implementing new authorization checks for RFC function modules. By activating these checks, organizations can ensure that only authorized users can execute specific RFC calls, thereby strengthening system security.
Affected areas include the authorization object F_CFIN_SRC, the scenario FIN_CFIN_SOURCE, and all remote-enabled function modules within the package FIN_CFIN_INTEGRATION.
Solution
- The new authorization checks are inactive by default to maintain system compatibility.
- Activate the checks using transaction SACF following the manual correction instructions attached to the note.
- After system updates, use transaction SACF_COMPARE to collectively maintain authorization scenarios.
- Ensure that all required authorizations are assigned to authorized users.
CVSS
Score 5.9 Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
References
Affected components
- S4CORE (versions 100, 101, 102)
- SAP_APPL (versions 600 to 616)
- SAP_FIN (versions 617 to 730)
Full note on SAP: SAP Support Launchpad note 2495144
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
