SAP security note 2266040, "Switchable Authorization Checks for RFC in CRM-MW-CCO". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Remote calls to RFC function modules are currently protected by checks on the authorization object S_RFC. However, these checks alone may not be sufficient for all RFC function modules, potentially allowing unauthorized access.
Solution
Activate the new switchable authorization checks and update the corresponding roles if the affected RFC function modules are included in your S_RFC authorizations. Use transaction SACF to create and activate the authorization scenario CRM_MW_MOB, choosing between Active or Logging status based on your requirements. Identify and update user roles to include the necessary authorizations for the new scenario.
References
Affected components
- BBPCRM, valid from release 700 to 715+
Full note on SAP: SAP Support Launchpad note 2266040
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




