SAP security note 1486759, "Blocking unauthorized access to system using TMSADM to 4.6B". Below are the symptom and SAP recommended solution.
Description
Symptom
Unauthorized accesses to the system using the user TMSADM are to be prevented. To prevent misuse, the password of the user TMSADM must be changed.
Solution
Make sure that either scenario 1 or 2 applies. Lock the user account TMSADM in the client 000.
After you lock it, the user TMSADM can no longer be used. The system then requests additional logon prompts in the Transport Management System (TMS), for example, when you display the import queue or distribute the configuration.
If the prerequisites (scenario 1 or scenario 2) do not apply, the following errors occur:
- Function: TMS_CI_CHECK_ACCESSTOKEN
- Message: RFC_COMMUNICATION_FAILURE
- Details: RFC communications error with system/destination TMSADM@<sys>.<domain> User is locked. Please notify the person responsible
Reason and prerequisites
A standard password is used. The standard password can be changed only as of Release 4.6C or higher. The following two scenarios are supported:
- Scenario 1: All systems in the landscape are treated the same with regard to TMSADM.
- Scenario 2: The system is not the domain controller and the other systems that have not been treated retain the standard password.
If neither of the two scenarios applies, the domains must be reconfigured to establish the prerequisite.
References
- 1515926 – Update #1 to Security Note 1414256
- 1504652 – Consulting: Secure Configuration of Application Server ABAP
- 1488406 – Handling the generated user TMSADM
- 1414256 – Changing TMSADM password is too complex
- 761637 – Logon restrictions prevent TMSADM logon
Full note on SAP: SAP Support Launchpad note 1486759
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



