Medium priority
SAP security note 2059230, "Authorization checks for RFC in E-Recruiting", is a note released on November 11, 2014. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Remote calls to RFC function modules were previously protected by the authorization object S_RFC. However, it was identified that these checks might not suffice to ensure secure execution for certain RFC function modules within E-Recruiting.
Solution
The security note implements additional authorization checks using existing authorization objects. Administrators should apply the attached correction instructions to ensure that authorizations for S_RFC are limited to the minimum necessary for all users. The affected RFC function module is HRRCF_MDL_ADMN_CHECK_EXT_CAND.
References
Affected components
- PA-ER (versions 600, 603, 604, 605, 606, 616, 617, 800, 801, 802)
Full note on SAP: SAP Support Launchpad note 2059230
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
