SAP Security Note
Medium priority
SAP security note 1423413, "Authorization check for FI-CA transactions FP03F/FP03L/FP03H", is a program error note released on 04.03.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
You can access the FI-CA transactions FP03L (List of Collection Items), FP03H (History of Collection Items), FP03U (Call Back Receivables from Collection Agency), and FP03I (Process Info from External Collection Agencies) even though you do not have the required authorization.
Solution
You can implement the solution in advance by importing the add-on releases that are specified in the validity section of this note. The corrections are usually delivered in the latest Add-On Support Package.
Reason and prerequisites
This problem is caused by a program error.
- Missing authorization checks in the application FI-CA for transactions FP03L, FP03H, FP03U, and FP03I enable you to read, change, and delete the data.
- The system does not issue error message >2 105 ("No authorization for activity &1 (&2)") for missing authorization checks.
References
This note refers to
Affected components
- FI-CA from 600 to 600
- FI-CA from 602 to 602
- FI-CA from 603 to 603
- FI-CA from 604 to 604
- FI-CA from 605 to 605
Full note on SAP: SAP Support Launchpad note 1423413
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



