High priority
SAP security note 1690942, "Missing Authorization Check in VIRSA and VIRSANH", is a note released on 12.06.2012. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of VIRSA and VIRSANH to which access should be restricted. This may result in an escalation of privileges.
Solution
In the GRC SPM application, the user exit SUSR0001 has been used to prevent the direct login of Fire Fighter IDs into the R/3 application. The include /virsa/zvirsa_userexit manages the prevention of FFIDs from direct login. However, this user exit can be bypassed.
To overcome this security gap, a Trusted RFC concept has been implemented in the SPM application. Benefits of Trusted RFC include that passwords are not required for logging in via RFC when an FFID logs into the system.
For trusted RFC settings, additional authorization details, and Fire Fighter Role modifications, please refer to the attachment.
Reason and prerequisites
VIRSA and VIRSANH do not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This may result in undesired system behavior.
References
Full note on SAP: SAP Support Launchpad note 1690942
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
