Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable authorization checks for RFC in SAP CRM (external billing), SAP security note 2541823

SAP Note 2541823
SAP Security Note
Medium priority

SAP security note 2541823, “Switchable authorization checks for RFC in SAP CRM (external billing)”, is a program error note released on 23.06.2020. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCRM-BTX-BF-EBI
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on23.06.2020
LanguageEnglish

Description

Symptom

UPDATE 23rd June 2020: This note has been re-released with the file CRM_SRV_EXT_BILLING.TXT added in the ‘attachment’ section.

This SAP note describes new switchable authorization checks for RFC function modules which are called from CRM reports in an external billing scenario.

Solution

New switchable authorization checks have been implemented. The checks are delivered inactive to ensure compatibility with your running processes. The checks can be activated in transaction SACF as described in the attached manual correction instruction. See SAP Note 1922808 for additional information on the switchable authorization check framework (SACF).

Affected function modules:

  • CRM_DELETE_OBSOLETE_DMR_ITEM
  • CRM_READ_DMR_ITEMS_FOR_CRM_SER
  • CRM_READ_DMR_ITEMS_FOR_CRM_W_D

New authorization scenario: CRM_SRV_EXT_BILLING (CRM External Billing RFC FM for Correction Reports). Authorization object: V_VBAK_AAT.

Reason and prerequisites

Remote calls to RFC function modules are protected by checks on the authorization object S_RFC. Authorizations for S_RFC must be limited to the required minimum for all users to ensure system security. Many RFC function modules can be sufficiently protected using S_RFC authorization checks, and often do not perform additional functional authorization checks. See SAP Note 2008727 for further information on RFC security.

It was identified that S_RFC authorization checks might not be sufficient to ensure secure execution for the RFC function modules covered by this note. Activate the new switchable authorization checks and update corresponding roles if these RFC function modules are included in S_RFC authorizations in your system.

CVSS

Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected components

  • S4CORE 102 (CRM-BTX-BF-EBI)
  • SAP_APPL 600-606, 616-618 (Toolbox external billing scenario: CRM_ANLYSE_SERVICE_DOC_DMR)

Full note on SAP: SAP Support Launchpad note 2541823

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More