Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable Authorization checks for RFC BCA_DIM_WRITE_OFF in Loans (FI-CAX-FS), SAP security note 2531131

SAP Note 2531131
SAP Security Note
Medium priority

SAP security note 2531131, “Switchable Authorization checks for RFC BCA_DIM_WRITE_OFF in Loans (FI-CAX-FS)”, is a program error note released on 27.02.2018. Below are the symptom and SAP recommended solution.

ComponentFinancial Accounting > Non-industry specific contract accounts receivable, payable > Integration Banking Services
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
StatusReleased for Customer
Released on27.02.2018

Description

Symptom

S_RFC authorization checks are not sufficient to ensure the secure execution of RFC function modules covered by this SAP Note. New switchable authorization checks have been implemented for RFC function modules in FI-CAX-FS.

Solution

New switchable authorization checks have been implemented and are delivered inactive to ensure compatibility with existing processes. These checks can be activated in transaction SACF following the manual correction instructions.

  • New Authorization Scenario: FS_TB_WRITEOFF – Scenario for Write Off functionality
  • Affected RFC Function Module: BCA_DIM_WRITE_OFF (Authorization Object: F_KKWOFF, Activity: ’10’ – Post)

Reason and prerequisites

Remote calls to RFC function modules are protected by the authorization object S_RFC. It’s essential to ensure that:

  • S_RFC authorizations are limited to the minimum required to maintain system security.
  • Many RFC function modules need additional functional authorization checks beyond S_RFC.

Prerequisites:

  • Implement SAP Note 2531511 for defining global variables for scenarios.
  • Implement SAP Note 2449051 for documentation of SACF scenarios.
  • Manual Pre-requisite: Implement SAP Note 2537070 – “Message class BCA_MCL_DIM_LOAN updated with new Message 061”.

CVSS

Score 0

Full note on SAP: SAP Support Launchpad note 2531131

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More