Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable Authorization checks for RFC in SAP Central Finance – Data Flow Verification, SAP security note 2690274

SAP Note 2690274SAP Security NoteMedium priority

SAP security note 2690274, "Switchable Authorization checks for RFC in SAP Central Finance – Data Flow Verification", is a note released on January 8, 2019. Below are the symptom and SAP recommended solution.

ComponentFinancial Accounting > Central Finance > Infrastructure, Tools, Mapping Framework
PriorityMedium priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released onJanuary 8, 2019

Description

Symptom

S_RFC authorization checks are not sufficient to ensure the secure execution of RFC function modules covered by this SAP Note. New switchable authorization checks have been implemented for RFC function modules in SAP Central Finance – Data Flow Verification.

Solution

New switchable authorization checks have been implemented and are delivered inactive to ensure compatibility with your current processes. These checks can be activated in transaction SACF as described in the attached manual correction instructions. For additional information on the switchable authorization check framework (SACF), refer to SAP Note 1922808.

Affected RFC function module: FIN_CFIN_DFV_CLR_MISSING_ITEM.

The switchable authorization checks are provided via support packages and can be technically pre-implemented using correction instructions. After implementation, the checks remain inactive until manually activated.

The switchable authorization check within FIN_CFIN_DFV_CLR_MISSING_ITEM relies on the scenario FIN_CFIN_SOURCE, delivered with SAP Note 2495144.

Reason and prerequisites

Remote calls to RFC function modules are by default protected by checks on the authorization object S_RFC. These checks must not be deactivated. Refer to SAP Note 2216306 for recommended and deprecated settings of the profile parameter auth/rfc_authority_check. Authorization for S_RFC must be limited to the minimum required for all users to ensure system security. Many RFC function modules can be sufficiently protected using S_RFC authorization checks and often do not perform additional functional authorization checks. For more information on RFC Security, see the white paper "Securing Remote Function Calls (RFC)" attached to SAP Note 2008727.

It has been identified that S_RFC authorization checks alone are not sufficient for secure execution of certain RFC function modules. Therefore, new switchable authorization checks need to be activated, and corresponding roles should be updated if these RFC function modules are included in your systems S_RFC authorizations.

Full note on SAP: SAP Support Launchpad note 2690274

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More