SAP security note 2029561, "Missing Authorization Check in IS-OIL", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Remote calls to RFC function modules in IS-OIL were found to lack sufficient authorization checks, potentially allowing unauthorized access and actions within the system.
Solution
- Implement new authorization checks: activate new authorization checks in transaction
SACF. Update roles to include the new authorization objectsO_DS_TXNfor transaction control andO_OIJ_SPTPfor modification controls related to rundown and rack forecasts. - Manual activities: if authorization object
O_DS_TXNdoes not exist, create it in transactionSU21with authorization fieldsTCDandACTVT. Use transactionSACF_TRANSFERto upload the scenario definitions from the attached files, assign the scenarios to the appropriate development packages, and activate them in productive mode (Active or Logging). - Adjust roles: analyze audit logs using report
RSAU_SELECT_EVENTSand update user roles to include the necessary authorizations based on the new scenarios. - Activate Security Audit Log: ensure security audit logging is enabled via transaction
SM19and configure filters to capture relevant authorization events.
Reason and prerequisites
The existing authorization object S_RFC may not provide adequate security for certain RFC function modules in IS-OIL. To mitigate this, new authorization checks are introduced that must be activated and configured appropriately.
References
This note refers to
Affected components
- IS-OIL (versions 600 to 617)
Full note on SAP: SAP Support Launchpad note 2029561
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
