SAP security note 2275009, "Switchable authorization checks for RFC in CRM-MW-ADP". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This SAP security note introduces new switchable authorization checks for RFC function modules SMOF_START_DOWNLOAD_OR_REQUEST and SMOF0_INIT_OBJ_SET_DNL_STAT_R within the CRM Middleware Adapter (CRM-MW-ADP). These checks enhance the security by ensuring that remote calls to RFC functions are adequately protected beyond the standard S_RFC authorization object.
Solution
To implement the new authorization checks, apply the provided support packages or correction instructions to pre-implement the checks. The checks will remain inactive post-installation.
- Step 1: Start transaction SACF in your development system. Verify if the scenario definition MWADP exists. If not, download the attachment MWADP.TXT and upload it via transaction SACF_TRANSFER. Assign the scenario to the development package SMOF.
- Step 2: Create the productive authorization scenario in SACF. Activate the switchable authorization checks as detailed in SAP Note 1922808.
CVSS
Score 6.3 / 10 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected components
- CRM-MW-ADP: BBPCRM 600 to 714
Full note on SAP: SAP Support Launchpad note 2275009
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




