Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable Authorization checks for RFC in Customer Master Data, SAP security note 2490047

SAP Note 2490047SAP Security NoteMedium priority

SAP security note 2490047, "Switchable Authorization Checks for RFC in Customer Master Data", is a program error note released on 08.01.2019. Below are the symptom and SAP recommended solution.

ComponentLogistics – General > Logistics Basic Data > Business Partners > Customer Master
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on08.01.2019
LanguageEnglish

Description

Symptom

Remote Function Call (RFC) function modules are protected by the authorization object S_RFC by default. However, for certain RFC function modules, S_RFC checks may not be sufficient. This note implements new switchable authorization checks that can be activated to provide enhanced security for these function modules.

Affected RFC function modules: BAPI_CUSTOMER_SEARCH, BAPI_CUSTOMER_SEARCH1, SDCA_CONTACT_VALUE_REQUEST.

Solution

  • The new authorization checks are delivered as inactive to maintain compatibility.
  • They can be activated using transaction SACF following the manual correction instructions.

CVSS

Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

References

Full note on SAP: SAP Support Launchpad note 2490047

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More