SAP Security Note
High priority
SAP security note 1529597, "Restricting authorization in CRM-MW-GWI", is a consulting note released on 14.05.2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of CRM-MW-GWI to which access should be restricted. This may result in an escalation of privileges.
Solution
Perform the steps outlined below.
- Create a new role
SAP_CRM_MW_GWIusing the transaction PFCG. - Add the following authorization objects to the newly created role and assign the Groupware Connector user the role
SAP_CRM_MW_GWI. Also, the Groupware Connector user should have the user type ‘Communications Data’.
SAP_CRM_MW_GWI: Role for groupware connector user ----------------------------------------------------------------------- Cross-application Authorization Objects ----------------------------------------------------------------------- Application | Authorization Object | Description ----------------------------------------------------------------------- Business Partner | B_BUPA_ATT | Authorization Types ----------------------------------------------------------------------- Parameters | * | ----------------------------------------------------------------------- Activity | All activities | ----------------------------------------------------------------------- Authorization type| * | ----------------------------------------------------------------------- Authorization value (field 1) | * | ----------------------------------------------------------------------- Authorization value (field 2) | * | -----------------------------------------------------------------------
Reason and prerequisites
CRM-MW-GWI user is not restricted by roles to check an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
Affected components
- BBPCRM: 500, 520, 600, 700, 701, 702, 712
Full note on SAP: SAP Support Launchpad note 1529597
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



