HotNews
SAP security note 1485029, "Protect Read Access to Key Tables", is released on October 28, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Insufficient authority checks may allow read access to tables containing cryptographic keys (PSE files).
Solution
Install the assigned support package. To apply the correction manually, follow these steps:
- Create Authorization Group SPSE: In all clients, execute transaction SE54. Select the radio button for "Authorization Groups" and click "Create/Change". Click "New entry" (F5) and enter the following values: AuGr: SPSE, Description: PSE files. Save the new record (a transport request is required).
- Modify Table SSF_PSE_D: For NW release 6.40 or newer: Execute transaction SE11 and display table SSF_PSE_D. Navigate to Utilities > Assign Authorization Group. Change the existing value in the "Authorization" column to SPSE. If no entry exists, create one and assign the authorization group SPSE. Save the changes. If prompted with "Choose the key from the allowed namespace", press Enter to continue. For NW release 6.20 or older: Execute transaction SM30 and maintain view V_DDAT_54. Insert the following line: SSF_PSE_D SPSE PSE-Files.
- Restrict Maintenance Access: Execute SE11 again for table SSF_PSE_D. Go to the "Delivery and Maintenance" tab. Set Data Browser/Table View Maintenance to "Display/Maintenance not Allowed". Activate the table after making changes.
- Verify Authorization Concept: Ensure that no user has generic table access to tables with the authorization group SPSE. Use report RSUSR002: Run the report and enter authorization object S_TABU_DIS in the "Selection by values" frame. Add SPSE in the search field for the authorization group. Execute the report. Use SUIM reports to identify responsible roles or profiles based on the report results.
References
- 1504652 – Consulting: Secure Configuration of Application Server ABAP
- 1497104 – Protect access to PSE files by additional AUTHORITY-CHECK
- 1484692 – Protect read access to password hash value tables
Affected components
- SAP_APPL: 45B
- SAP_BASIS: 46A to 46D, 610 to 640, 700 to 702, 710 to 720, 72L
Full note on SAP: SAP Support Launchpad note 1485029
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



