Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable authorization checks for RFC in CRM-MW-MFW, SAP security note 2270084

SAP Note 2270084

SAP security note 2270084, "Switchable authorization checks for RFC in CRM-MW-MFW". Below are the symptom and SAP recommended solution.

Description

Symptom

Existing S_RFC authorization checks may not be sufficient to ensure secure execution for certain RFC function modules in CRM-MW-MFW. This can potentially lead to unauthorized data migrations or processing if not properly managed.

Solution

The note provides new switchable authorization checks that are initially inactive to maintain compatibility with current processes. Administrators can activate these checks via the SACF transaction. The activation involves:

  • Implementing the Switchable Authorization Checks: Execute the correction instructions provided in the support package.
  • Activating the Authorization Checks: Use transaction SACF to create a productive authorization scenario from the scenario definition. Choose between "Active" or "Logging" statuses depending on your monitoring needs.
  • Adjusting User Roles: Identify and grant necessary authorizations to users based on the new authorization scenario using reports like RSAU_SELECT_EVENTS.

Full note on SAP: SAP Support Launchpad note 2270084

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More