SAP security note 2490047, "Switchable Authorization Checks for RFC in Customer Master Data", is a program error note released on 08.01.2019. Below are the symptom and SAP recommended solution.
Description
Symptom
Remote Function Call (RFC) function modules are protected by the authorization object S_RFC by default. However, for certain RFC function modules, S_RFC checks may not be sufficient. This note implements new switchable authorization checks that can be activated to provide enhanced security for these function modules.
Affected RFC function modules: BAPI_CUSTOMER_SEARCH, BAPI_CUSTOMER_SEARCH1, SDCA_CONTACT_VALUE_REQUEST.
Solution
- The new authorization checks are delivered as inactive to maintain compatibility.
- They can be activated using transaction SACF following the manual correction instructions.
CVSS
Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
References
- Securing Remote Function Calls (RFC) White Paper
- 2373735 – DEBI and KRED search helps do not check authorizations
Full note on SAP: SAP Support Launchpad note 2490047
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




