SAP security note 2035310, “Switchable authorization check in FI-GL-GL-ACE”, is a note. Below is the security information published by SAP for this note.
Description
Symptom
An authenticated user can use functions of FI-LA to which access should be restricted. This may result in an escalation of privileges.
Reason and prerequisites
Transactions S_XB7_96000248, S_XB7_96000249, and S_XB7_96000239 do not sufficiently check authenticated user's authorizations. When accessing the result list, the authorization is not checked on the company code level.
Solution
New switchable authorization scenarios are implemented with this note. The checks are delivered inactive to avoid disruptions of your current processes. The checks can be activated in transaction SACF. You must have implemented the switchable authorization check framework (SACF) in your system if you want to use this check. For information about the installation of the SACF workbench, see SAP Note 1908870.
For further information about the SACF functionality, please refer to the SAP Online Help.
Changed Authorization Scenario(s)
The following authorization scenarios are extended with this note and can be maintained in transaction SACF:
- Scenario FI_ACE_REPORT: With this scenario, checks on authorization objects F_ACE_DST and F_ACE_PST can be activated, improving the accuracy of authorization checks for the affected transactions.
Full note on SAP: SAP Support Launchpad note 2035310
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
