SAP Security Note
Medium priority
SAP security note 2531131, “Switchable Authorization checks for RFC BCA_DIM_WRITE_OFF in Loans (FI-CAX-FS)”, is a program error note released on 27.02.2018. Below are the symptom and SAP recommended solution.
Description
Symptom
S_RFC authorization checks are not sufficient to ensure the secure execution of RFC function modules covered by this SAP Note. New switchable authorization checks have been implemented for RFC function modules in FI-CAX-FS.
Solution
New switchable authorization checks have been implemented and are delivered inactive to ensure compatibility with existing processes. These checks can be activated in transaction SACF following the manual correction instructions.
- New Authorization Scenario: FS_TB_WRITEOFF – Scenario for Write Off functionality
- Affected RFC Function Module: BCA_DIM_WRITE_OFF (Authorization Object: F_KKWOFF, Activity: ’10’ – Post)
Reason and prerequisites
Remote calls to RFC function modules are protected by the authorization object S_RFC. It’s essential to ensure that:
- S_RFC authorizations are limited to the minimum required to maintain system security.
- Many RFC function modules need additional functional authorization checks beyond S_RFC.
Prerequisites:
- Implement SAP Note 2531511 for defining global variables for scenarios.
- Implement SAP Note 2449051 for documentation of SACF scenarios.
- Manual Pre-requisite: Implement SAP Note 2537070 – “Message class BCA_MCL_DIM_LOAN updated with new Message 061”.
CVSS
Score 0
Full note on SAP: SAP Support Launchpad note 2531131
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
