SAP security note 2052113, "Switchable Authorization Checks for RFC in CRM-MW-ADP", is a note. Below are the SAP recommended solution and the affected software components.
Description
Solution
The note implements switchable authorization checks that are initially inactive to maintain compatibility. To activate these checks, follow the manual correction instructions provided in the note.
- Activate Authorization Checks: use transaction
SACFto activate the new authorization scenarios as detailed in the manual actions section of the note. - Adjust User Roles: update roles to include the new authorization objects to ensure users have the necessary permissions.
References
- Further improvements for RFC security
- SACF: Navigation error
- Check whether a function module was called via external RFC
Affected components
- PI_BASIS (versions 2005_1_700 to 740)
- SAP_BASIS (versions 700 to 740)
Full note on SAP: SAP Support Launchpad note 2052113
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
