Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization check in RFC Destination Maintenance, SAP security note 2417355

SAP Note 2417355
SAP Security Note
Medium priority

SAP security note 2417355, "Missing Authorization check in RFC Destination Maintenance", is a program error note released on 2017.04.11. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Middleware > RFC (BC-MID-RFC)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on2017.04.11
LanguageEnglish

Description

Symptom

RFC Destination Maintenance does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Some well-known impacts of Missing Authorization check are:

  • Abuse functionality restricted to a particular user group
  • Read, modify, or delete restricted data

Solution

The correction provided in this note overcomes the gap and extends the authorization check S_RFC_ADM for the field ICF_VALUE.

Please implement the Support Package mentioned in this SAP Note, or apply the respective correction instructions. You can download the necessary support packages and find more information here.

Reason and prerequisites

A user with correct permission to access RFC Destination Maintenance (SM59) is required.

In cases where the user is restricted to editing only some of the RFC Destinations by additional authorization values, the user may overcome this restriction by navigating inside SM59. This will enable the user to maintain RFC Destinations not authorized for.

CVSS

Score 4.70 Vector: NLHN | U | LLL (CVSS v3.0)

Full note on SAP: SAP Support Launchpad note 2417355

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More