Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable authorization checks for RFC in data extraction within CA-MDG-APP-FIN, SAP security note 2185122

SAP Note 2185122
SAP Security Note
Low priority

SAP security note 2185122, "Switchable Authorization Checks for RFC in Data Extraction within CA-MDG-APP-FIN", is a program error note released on July 6, 2017. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCA-MDG-APP-FIN (Cross-Application Components > Master Data Governance > Applications > MDG Financials)
CategoryProgram Error
PriorityCorrection with Low Priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onJuly 6, 2017

Description

Symptom

This SAP Note introduces new switchable authorization checks for RFC function modules in CA-MDG-APP-FIN, specifically targeting data extraction function modules. The enhancement ensures that remote calls to RFC function modules are protected by additional authorization object checks, thereby strengthening system security.

Solution

New switchable authorization checks have been implemented but remain inactive by default to maintain compatibility with existing processes.

References

Affected components

  • MDG_FND (731 to 800)
  • SAP_BASIS (700 to 740, specific support package levels)

Full note on SAP: SAP Support Launchpad note 2185122

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More