SAP security note 2072641, “Authorization checks for RFC in Patient Register”, is a note. Below is the security information published by SAP for this note.
Description
This SAP Security Note introduces enhanced authorization checks for RFC function modules used in patient-dependent search and correction reports within the patient register. The update ensures that remote calls to RFC function modules are secured not only by the existing S_RFC authorization checks but also by additional Patient-Authority checks, thereby strengthening overall system security.
Reason and prerequisites
- Issue Identified: The existing S_RFC authorization checks were insufficient to guarantee the secure execution of certain RFC function modules.
- Enhancement: Introduction of Patient-Authority checks provides an extra layer of security.
- Prerequisites: No changes are required to existing user authorizations, ensuring seamless integration without additional configuration.
Solution
Implement the provided correction instructions to activate the new authorization checks. Detailed steps can be found in the Correction Instructions section of the note.
Additional information
- SAP Component: IS-H (Industry-Specific Components > Hospital)
- Version: 4
- Release Status: Released for Customer on 11.11.2014
- Priority: Correction with medium priority
- References: For further improvements on RFC security, refer to SAP Note 2078596.
For more details, visit the SAP Notes portal.
*Credits to redrays.io for supporting the provision of this information.*
Full note on SAP: SAP Support Launchpad note 2072641
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
