Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable authorization check in FI-GL-GL-ACE, SAP security note 2035310

SAP Note 2035310

SAP security note 2035310, “Switchable authorization check in FI-GL-GL-ACE”, is a note. Below is the security information published by SAP for this note.

Description

Symptom

An authenticated user can use functions of FI-LA to which access should be restricted. This may result in an escalation of privileges.

Reason and prerequisites

Transactions S_XB7_96000248, S_XB7_96000249, and S_XB7_96000239 do not sufficiently check authenticated user's authorizations. When accessing the result list, the authorization is not checked on the company code level.

Solution

New switchable authorization scenarios are implemented with this note. The checks are delivered inactive to avoid disruptions of your current processes. The checks can be activated in transaction SACF. You must have implemented the switchable authorization check framework (SACF) in your system if you want to use this check. For information about the installation of the SACF workbench, see SAP Note 1908870.

For further information about the SACF functionality, please refer to the SAP Online Help.

Changed Authorization Scenario(s)

The following authorization scenarios are extended with this note and can be maintained in transaction SACF:

  • Scenario FI_ACE_REPORT: With this scenario, checks on authorization objects F_ACE_DST and F_ACE_PST can be activated, improving the accuracy of authorization checks for the affected transactions.

Full note on SAP: SAP Support Launchpad note 2035310

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More