SAP Security Note
Medium priority
SAP security note 2027997, "Authorization check for RFC in FIN-FSCM-TRM-TM-TR", is a program error note released on 24.10.2014. Below are the symptom and SAP recommended solution.
Description
Symptom
This SAP Note describes a new authorization checks for an RFC function module in Treasury and Risk management.
Solution
New authorization checks have been implemented.
Reason and prerequisites
Remote calls to RFC function modules are protected by checks on the authorization object S_RFC. Authorizations for S_RFC must be limited to the required minimum authorizations for all users to ensure system security. Many RFC function modules can be sufficiently protected using S_RFC authorization checks. These RFC function modules often do not perform additional functional authorization checks.
It was identified that S_RFC authorization checks might not be sufficient to ensure secure execution for RFC function modules covered by this SAP Note.
References
Full note on SAP: SAP Support Launchpad note 2027997
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



