Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Authorization check for FI-CA transactions FP03F/FP03L/FP03H, SAP security note 1423413

SAP Note 1423413
SAP Security Note
Medium priority

SAP security note 1423413, "Authorization check for FI-CA transactions FP03F/FP03L/FP03H", is a program error note released on 04.03.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentFI-CA
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on04.03.2010
LanguageEnglish

Description

Symptom

You can access the FI-CA transactions FP03L (List of Collection Items), FP03H (History of Collection Items), FP03U (Call Back Receivables from Collection Agency), and FP03I (Process Info from External Collection Agencies) even though you do not have the required authorization.

Solution

You can implement the solution in advance by importing the add-on releases that are specified in the validity section of this note. The corrections are usually delivered in the latest Add-On Support Package.

Reason and prerequisites

This problem is caused by a program error.

  • Missing authorization checks in the application FI-CA for transactions FP03L, FP03H, FP03U, and FP03I enable you to read, change, and delete the data.
  • The system does not issue error message >2 105 ("No authorization for activity &1 (&2)") for missing authorization checks.

References

Affected components

  • FI-CA from 600 to 600
  • FI-CA from 602 to 602
  • FI-CA from 603 to 603
  • FI-CA from 604 to 604
  • FI-CA from 605 to 605

Full note on SAP: SAP Support Launchpad note 1423413

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More