SAP security note 2527346, "Switchable Authorization checks for SAP ERP". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 2527346 addresses the insufficiency of S_RFC authorization checks for securing the execution of RFC function modules in Records Management and Guaranteed Minimum. This note introduces new switchable authorization checks that enhance system security by allowing these checks to be activated as needed.
Solution
New authorization scenarios are implemented but remain inactive by default to ensure compatibility. Activation can be performed via transaction SACF.
- Part 1: Creation of Scenario Definitions – Execute the report /SAPPSPRO/NOTE_2527346 using transaction SE38.
- Part 2: Creating Productive Authorization Scenarios – Use transaction SACF to transfer scenario definitions to productive scenarios. Choose the status Active to enforce authorization checks or Logging to monitor without enforcing.
- Part 3: Activate Logging – Ensure Security Audit Log is activated in transaction SM19. Activate message IDs DUO, DUP, and DUQ for detailed logging.
- Part 4: Adjust User Roles – Identify and assign necessary authorizations to users based on audit logs using report RSAU_SELECT_EVENTS.
CVSS
Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
References
- SAP Note 2216306 for profile parameter recommendations.
- SAP Note 1922808 for information on the SACF framework.
- Securing Remote Function Calls (RFC) White Paper attached to SAP Note 2008727.
Affected components
- SAP_APPL (Releases 600 to 618)
- S4CORE (Releases 100 to 102)
- SAP_BASIS (Various Releases)
Full note on SAP: SAP Support Launchpad note 2527346
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
