Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Restricting authorization in CRM-MW-GWI, SAP security note 1529597

SAP Note 1529597
SAP Security Note
High priority

SAP security note 1529597, "Restricting authorization in CRM-MW-GWI", is a consulting note released on 14.05.2013. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCustomer Relationship Management > Middleware > Groupware Integration
CategoryConsulting
PriorityCorrection with high priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on14.05.2013

Description

Symptom

An authenticated user can use functions of CRM-MW-GWI to which access should be restricted. This may result in an escalation of privileges.

Solution

Perform the steps outlined below.

  • Create a new role SAP_CRM_MW_GWI using the transaction PFCG.
  • Add the following authorization objects to the newly created role and assign the Groupware Connector user the role SAP_CRM_MW_GWI. Also, the Groupware Connector user should have the user type ‘Communications Data’.
SAP_CRM_MW_GWI: Role for groupware connector user
-----------------------------------------------------------------------
Cross-application Authorization Objects
-----------------------------------------------------------------------
Application       | Authorization Object | Description
-----------------------------------------------------------------------
Business Partner  | B_BUPA_ATT            | Authorization Types
-----------------------------------------------------------------------
Parameters        | *                     |
-----------------------------------------------------------------------
Activity          | All activities        |
-----------------------------------------------------------------------
Authorization type| *                     |
-----------------------------------------------------------------------
Authorization value (field 1) | *              |
-----------------------------------------------------------------------
Authorization value (field 2) | *              |
-----------------------------------------------------------------------

Reason and prerequisites

CRM-MW-GWI user is not restricted by roles to check an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.

Affected components

  • BBPCRM: 500, 520, 600, 700, 701, 702, 712

Full note on SAP: SAP Support Launchpad note 1529597

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More