SAP Security Note
SAP security note 2539437, “Switchable authorization checks for RFC in SAP CRM (MSE R3-EDITION )”, is a note released on June 8, 2020. Below are the symptom and SAP recommended solution.
Description
Symptom
Remote calls to RFC function modules in the CRM MSE Mobile solution (R3 Edition) were protected only by the S_RFC authorization object. It was identified that these checks might not be sufficient for certain RFC function modules, which could allow calls without adequate functional authorization checks.
Solution
New switchable authorization checks have been implemented for RFC function modules used in CRM reports within the CRM MSE Mobile solution (R3 Edition). The new checks are delivered inactive to ensure compatibility and require manual activation via transaction SACF.
Affected function modules:
- CRM_CS_API_ORDER_CREATE
- CRS_CONF_CREATE_TIMECONF
- CRS_NOTIF_UPLOAD_CHANGE_PROXY
- CRS_NOTIF_UPLOAD_PROXY
- CRS_SM_CONF_UPLOAD_PROXY
- CRS_SORDER_CREATE_UPLOAD_PROXY
- ICSM_WORKCENTER_READ_MULTIPLE
Use transaction SACF to activate the new switchable authorization checks, following the manual correction instructions attached to the note. Perform the manual activities separately in each system where the note is transported, creating a productive authorization scenario from the scenario definition.
CVSS
Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Full note on SAP: SAP Support Launchpad note 2539437
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
