Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Authorization checks for RFC in CRM-MKT-MPL-ST-ERP, SAP security note 2049681

SAP Note 2049681
SAP Security Note
Medium priority

SAP security note 2049681, "Authorization checks for RFC in CRM-MKT-MPL-ST-ERP", is a program error note released on November 11, 2014. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCustomer Relationship Management > Marketing > Marketing Planner > Basic Functions > ERP-Interface
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released onNovember 11, 2014
LanguageEnglish

Description

Symptom

This SAP Note provides existing authorization checks for RFC function modules in CRM-MKT-MPL-ST-ERP.

Solution

Existing authorization checks have been implemented. The affected RFC function module is READ_ERP_MARKETING_PROMOTIONS. The authorization checks are provided via support package and can be technically pre-implemented via the correction instructions. After technical implementation via support package or correction instructions, the checks will be active.

Reason and prerequisites

Remote calls to RFC function modules are protected by checks on the authorization object S_RFC. Authorizations for S_RFC must be limited to the required minimum authorizations for all users to ensure system security. Many RFC function modules can be sufficiently protected using S_RFC authorization checks. These RFC function modules often do not perform additional functional authorization checks. Please see SAP Note 2008727 for further information on RFC Security. It was identified that S_RFC authorization checks might not be sufficient to ensure secure execution for RFC function modules covered by this SAP Note.

CVSS

Score 0

References

Affected components

  • SAP_APPL (versions 600, 602, 603, 604, 605, 606, 616, 617)

Full note on SAP: SAP Support Launchpad note 2049681

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More