SAP Security Note
Medium priority
SAP security note 2522527, "Switchable authorization checks for RFC of SD/FI-CA integration for distributed systems", is a note released on August 2, 2018. Below are the symptom and SAP recommended solution.
Description
Symptom
The note addresses the need to activate new authorization checks for specific RFC function modules used in the integration between Sales & Distribution (SD) and Contract Accounts Receivable and Payable (FI-CA) across distributed systems. By default, these checks are inactive to maintain compatibility with existing processes but can be activated to enhance security.
Solution
Activation of Authorization Checks:
- Access transaction SACF to verify the existence of the scenario definition SD_FKK_DISTR_SYS.
- If absent, download the SD_FKK_DISTR_SYS.TXT attachment.
- Use transaction SACF_TRANSFER to upload and assign the scenario definition to the development package VFKK_OBJECTS.
- Follow the detailed steps provided in the manual activities section of the note to complete the activation.
Affected RFC Function Modules: VFKK_RFC_CONSISTENCY_CHECK, VFKK_RFC_READ_DOCSTAT, VFKK_RFC_SET_DOCSTAT_FOR_SD, VFKK_RFC_UPDATE_VBRK, VFKK_RFC_READ_VBRK, VFKK_RFC_SET_RFBSK_FOR_SD. These modules are integral to ensuring the consistency and status updates of SD invoices in the central FI-CA system.
Implementation Steps:
- Verify and create the authorization scenario in your development system via SACF.
- Activate the switchable authorization checks post system updates using SACF_COMPARE.
For a comprehensive guide, refer to the manual activities section within the SAP Note.
References
- SAP Note 2216306 – Recommended and obsolete settings of the profile parameter auth/rfc_authority_check.
- SAP Note 2008727 – Whitepaper on Securing Remote Function Calls (RFC).
- SAP Note 1922808 – Switchable framework for authorization checks (SACF).
Full note on SAP: SAP Support Launchpad note 2522527
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



