Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CO-OM tools SE16N Deactivating &SAP_EDIT, SAP security note 1420281

SAP Note 1420281

SAP security note 1420281, "Deactivate &SAP_EDIT in SE16N to Enhance Security". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The &SAP_EDIT function in SE16N allowed users with certain authorizations to switch to change mode, which was not intended for all users.

Solution

Implementing this security note will completely deactivate the &SAP_EDIT function, thereby eliminating the risk of unauthorized changes through SE16N. You can implement this security enhancement using SNOTE or by downloading the patch directly.

For systems running on Release 600, the necessary source code corrections are included in Support Package 17 and Support Package 18. It’s recommended to apply these updates to ensure comprehensive protection.

Reason and prerequisites

Although &SAP_EDIT was protected by high-level developer authorization, its availability on the internet led to unauthorized access and potential security breaches within customer environments.

References

Affected components

  • SAP_APPL 46C
  • SAP_APPL 470
  • SAP_APPL 500
  • SAP_APPL 600 (including Support Packages 17 & 18)
  • SAP_APPL 602
  • SAP_APPL 603
  • SAP_APPL 604

Full note on SAP: SAP Support Launchpad note 1420281

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More