SAP Security Note
Medium priority
SAP security note 2989719, "Missing Authorization check in S/4HANA (Central Finance)", is a program error note released on 24.11.2020. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP security note 2495144 introduces a new authorization concept for Central Finance, which includes the manual creation of the authorization object F_CFIN_SRC. However, in some releases, manual creation of authorization objects within the SAP namespace is not possible. This necessitates a report that automatically creates the required authorization object.
Solution
This correction applies to the source system(s).
- Implement the Correction Instruction: download the correction instruction from Download for SNOTE.
- Run the Report: execute the report provided in the correction instruction to automatically create the authorization object F_CFIN_SRC.
- Resume Implementation: after successfully creating the authorization object, proceed with the implementation of SAP Note 2495144.
Reason and prerequisites
The inability to manually create authorization objects in certain SAP releases.
CVSS
Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Full note on SAP: SAP Support Launchpad note 2989719
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
