Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable authorization checks for RFC module in In-House-Cash., SAP security note 2743329

SAP Note 2743329

SAP security note 2743329, "Switchable authorization checks for RFC module in In-House-Cash.", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

UPDATE 9th February 2021: This note has been re-released with the updated ‘validity’ information. We added the validity for the releases – S4CORE 102, S4CORE 103, S4CORE 104.

This note describes switchable authorization checks for RFC module IHC_PN_ST_INFO_GET in the In House Cash Application.

Remote calls to RFC function modules are protected by checks on the authorization object S_RFC. Authorizations for S_RFC must be limited to the required minimum authorizations for all users to ensure system security. Many RFC function modules can be sufficiently protected using S_RFC authorization checks. These RFC function modules often do not perform additional functional authorization checks. Please see SAP Note 2008727 for further information on RFC Security.

It was identified that S_RFC authorization checks might not be sufficient to ensure secure execution for RFC function modules covered by this note. Activate new switchable authorization checks and update corresponding roles if these RFC function modules are included in S_RFC authorizations in your system.

Solution

New switchable authorization checks have been implemented. The checks are delivered inactive to ensure compatibility with your running processes. The checks can be activated in transaction SACF as described in the attached manual correction instruction.

New Authorization Scenarios that can be maintained in transaction SACF after implementing this SAP note:

  • IHC_PN – In House Cash Payment Order and Item actions
  • IHC_PRQ – In House Cash Payment Request actions and Document Reversal

Affected Business Processes and Roles: when checking the status of a payment order, ensure that the user processing the payment order has the necessary authorization to perform the action.

Affected RFC Function Module:

  • IHC_PN_ST_INFO_GET

CVSS

Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected components

  • S4CORE 102
  • S4CORE 103
  • S4CORE 104

Full note on SAP: SAP Support Launchpad note 2743329

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More