SAP security note 1432456, "Adjusting role templates: S_RS_HYBR and S_RS_LPOA added", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
1. You use the role template S_RS_RDEMO or S_RS_ROPOP to set up roles. However, after assigning the roles, users lack authorization for HybridProviders (S_RS_HYBR) or semantically partitioned InfoProviders (S_RS_LPOA).
2. You use the role template "S_RS_RDEAD: BI role: BI Administrator (development system)". This template grants assigned users authorization for all transactions (S_TCODE = "*"). This poses security risks.
Solution
To address the issues, you can either import the necessary Support Package or perform the following manual changes:
1. Import Support Package
Software Component: SAP NetWeaver BW 7.20. Support Package: SAPKW72003. Import Support Package 03 for SAP NetWeaver BW 7.20 (SAPKW72003) into your BW system. This Support Package becomes available once Note 1407599 "SAPBINews NW BI 7.2 ABAP SP03" is released for customers.
2. Manual Changes
Transaction: PFCG. Menu: Utilities → Templates.
- Modify S_RS_DEMO Template: Select the template S_RS_DEMO and choose Change. Choose Manual input and add the authorization objects S_RS_HYBR and S_RS_LPOA. Assign full authorization (*) for all fields.
- Modify S_RS_ROPOP Template: Select the template S_RS_ROPOP and repeat the steps above.
- Modify S_RS_RDEAD Template: Select the template S_RS_RDEAD. Expand the node Cross-application Authorization Objects (AAAB) and select the authorization object Transaction Code Check at Transaction Start (S_TCODE). Remove the existing full authorization and add the following values in the "From" column: LIST*, RSA*, RSBO_EXTRACT, RSD1 (set the "To" value to RSDIOBCM), RSHIERINT, RSI0, RSIC, RSICUBE, RSMO, RSS*, RSU*, SU53.
Reason and prerequisites
The authorizations S_RS_LPOA and S_RS_HYBR are missing from the role templates S_RS_RDEMO and S_RS_ROPOP. Importing the specified Support Package will make these authorizations available.
CVSS
Score 0
Full note on SAP: SAP Support Launchpad note 1432456
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



