SAP Security Note
Medium priority
SAP security note 2355398, “Missing Authorization check in RFC function module”, is a program error note released on 25.01.2017. Below are the symptom and SAP recommended solution.
Description
Symptom
Flexible Solution Billing (FSB) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of a missing authorization check include:
- Abuse of functionality restricted to a particular user group
- Ability to read, modify, or delete restricted data
Solution
The corresponding authority check is now included in the RFC.
- Apply the correction instruction available here.
- Update roles: check and, if necessary, adopt your roles with the authorization object
/SOIN/FUNC, maintaining the valueACTVT = 01.
Ensure that all relevant systems are updated to include the new authorization checks to prevent unauthorized privilege escalation.
Reason and prerequisites
No authority check within the RFC.
Full note on SAP: SAP Support Launchpad note 2355398
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
