Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization check in RFC function module, SAP security note 2355398

SAP Note 2355398
SAP Security Note
Medium priority

SAP security note 2355398, “Missing Authorization check in RFC function module”, is a program error note released on 25.01.2017. Below are the symptom and SAP recommended solution.

ComponentSales and Distribution > Billing > Processing Billing Documents > Consolidated Billing
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on25.01.2017
LanguageEnglish

Description

Symptom

Flexible Solution Billing (FSB) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Some well-known impacts of a missing authorization check include:

  • Abuse of functionality restricted to a particular user group
  • Ability to read, modify, or delete restricted data

Solution

The corresponding authority check is now included in the RFC.

  • Apply the correction instruction available here.
  • Update roles: check and, if necessary, adopt your roles with the authorization object /SOIN/FUNC, maintaining the value ACTVT = 01.

Ensure that all relevant systems are updated to include the new authorization checks to prevent unauthorized privilege escalation.

Reason and prerequisites

No authority check within the RFC.

Full note on SAP: SAP Support Launchpad note 2355398

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More