SAP security note 2062186, “Switchable authorization checks for RFC in ESS_USERS_OF_ROLE_GET”, is a program error note released on 01.12.2014. Below is the security information published by SAP for this note.
Description
Symptom
This SAP note describes new switchable authorization checks for RFC function modules in the function ESS_USERS_OF_ROLE_GET.
Reason and prerequisites
Remote calls to RFC function modules are protected by checks on the authorization object S_RFC. Authorizations for S_RFC must be limited to the required minimum authorizations for all users to ensure system security. Many RFC function modules can be sufficiently protected using S_RFC authorization checks. These RFC function modules often do not perform additional functional authorization checks. Please see SAP Note 2008727 for further information on RFC Security.
It was identified that S_RFC authorization checks might not be sufficient to ensure secure execution for RFC function modules covered by this note. Activate new switchable authorization checks and update corresponding roles if these RFC function modules are included in S_RFC authorizations in your system.
The note 2044543 should be implemented in your system.
Solution
New switchable authorization checks have been implemented. The checks are delivered inactive to ensure compatibility with your running processes. The checks can be activated in transaction SACF as described in SAP Note 2044543.
New authorization scenario(s): The following new authorization scenarios can be maintained in transaction SACF after implementation of this SAP note.
Scenario 1 HRBAS_ESS: see SAP Note 2044543.
Affected RFC function modules: ESS_USERS_OF_ROLE_GET
References
- 2078596 – Further improvements for RFC security
- 2044543 – Switchable authorization checks for RFC in Workflow and ESS
Full note on SAP: SAP Support Launchpad note 2062186
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



