Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Protect access to PSE files by additional AUTHORITY-CHECK, SAP security note 1497104

SAP Note 1497104SAP Security NoteHotNews

SAP security note 1497104, "Protect access to PSE files by additional AUTHORITY-CHECK", is a program error note released on 14.09.2010. Below are the symptom and SAP recommended solution.

ComponentSecure Store and Forward (BC-SEC-SSF)
CategoryProgram error
PriorityHotNews
TypeSAP Security Note
Version6
StatusReleased for Customer
Released on14.09.2010
LanguageEnglish

Description

Symptom

Insufficient authorization checks may allow ABAP programs to access PSE files.

Solution

Install the relevant kernel patch for your SAP release:

  • Kernel 4.0B PL #1075 (or higher)
  • Kernel 4.5B PL #1006 (or higher)
  • Kernel 4.6D PL #2540 (or higher)
  • Kernel 6.40 PL #342 (or higher)
  • Kernel 7.00 PL #268 (or higher)
  • Kernel 7.01 PL #106 (or higher)
  • Kernel 7.10 PL #212 (or higher)
  • Kernel 7.11 PL #098 (or higher)
  • Kernel 7.20 PL #061 (or higher)

After applying the correction, the system will allow access to PSE files (i.e., files ending with .pse) and the file cred_v2 only after a successful authorization check for the object S_RZL_ADM with the field ACTVT and value 01, in addition to the S_DATASET and S_PATH authorization checks. These authorizations are included in the authorization proposals (see transaction SU24) for transaction STRUST.

CVSS

Score 0

References

Full note on SAP: SAP Support Launchpad note 1497104

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More