Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security gap in the Workflow Customizing, SAP security note 149344

SAP Note 149344
SAP Security Note
High priority

SAP security note 149344, "Security gap in the Workflow Customizing", was released on 08.10.2009. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Business Management > Business Workflow
PriorityCorrection with high priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on08.10.2009

Description

Symptom

In the Business Workflow area, the automatic customizing process creates a user named WF-BACKGROUND. This user is assigned the SAP_ALL and SAP_NEW authorizations because all background steps in the workflow are executed under this user. The security issue arises because user administrators with the lesser S_A.ADMIN standard profile can create a 'dialog user' from the WF-BACKGROUND user. This indirectly grants them SAP_ALL authorization, potentially leading to unauthorized access and elevated privileges within the system.

This vulnerability allows individuals with the S_A.ADMIN profile to gain full system authorizations (SAP_ALL) by leveraging the ability to create dialog users from the WF-BACKGROUND account. This can result in unauthorized access, data breaches, and compromise of system integrity.

Solution

  • Assign to SUPER user group: assign the WF-BACKGROUND user to the SUPER user group, and ensure that administrators do not belong to the SUPER user group to prevent unauthorized changes to the WF-BACKGROUND user.
  • Execute source code correction: apply the provided source code correction so that the WF-BACKGROUND user is created with the SUPER user group from the outset, guaranteeing that the user does not receive excessive authorizations during the automatic customizing process.

Full note on SAP: SAP Support Launchpad note 149344

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More