Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable Authorization checks in SAP ERP, SAP security note 2496977

SAP Note 2496977
Medium priority

SAP security note 2496977, "Switchable Authorization checks in SAP ERP", is a note released on June 11, 2019. Below are the symptom and the SAP recommended solution.

ComponentPublic Sector Management > Procurement for Public Sector (PSM-GPR)
PriorityMedium priority
Released onJune 11, 2019

Description

Symptom

SAP Security Note 2496977 addresses the insufficiency of existing S_RFC authorization checks in ensuring the secure execution of certain RFC function modules. This note introduces new switchable authorization checks for RFC function modules related to reading Material, Purchase Order (PO), and Company Code data, enhancing the overall security posture of your SAP ERP system.

The default S_RFC authorization checks are inadequate for securely executing the RFC function modules covered by this note. This can potentially allow unauthorized access or actions within the system.

Solution

Implement the new switchable authorization checks as outlined in the security note. This involves downloading and applying the provided support packages, following correction instructions, and activating the new authorization scenarios.

  • Apply Correction Instructions: Access the Correction Instructions specific to your software component.
  • Activate Switchable Authorization Checks: Use transaction SACF_COMPARE to activate the new authorization checks after applying the support packages. Follow the detailed manual activities provided in the security note to ensure proper activation and configuration.
  • Update User Roles: Adjust user roles to incorporate the new authorization scenarios. Utilize transactions STAUTHTRACE or ST01 to analyze and verify authorization checks.

CVSS

Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

References

Full note on SAP: SAP Support Launchpad note 2496977

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More