Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable authorization checks for RFC in IS-M, part 2, SAP security note 2061519

SAP Note 2061519

SAP security note 2061519, “Switchable authorization checks for RFC in IS-M, part 2 (SAP Note 2061519)”, is a note. Below is the security information published by SAP for this note.

Description

Overview

SAP Note 2061519 introduces new switchable authorization checks for RFC function modules in IS-Media (IS-M). This enhancement ensures more robust security by supplementing existing authorization objects.

Symptom

Remote Function Calls (RFC) to function modules in IS-Media were previously protected solely by the authorization object S_RFC. It was identified that these checks might not be sufficient for secure execution, necessitating additional authorization mechanisms.

Reason and prerequisites

  • Issue Identified: The existing S_RFC authorization checks do not provide adequate security for certain RFC function modules.
  • Prerequisite: SAP Note 2022888 ("Switchable authorization checks for RFC in IS-M") must be applied prior to this note.

Solution

New switchable authorization checks have been implemented and delivered inactive to maintain compatibility with ongoing processes. These checks can be activated using transaction SACF as per the provided manual correction instructions.

Additional information

For a PDF version of the note, visit PDF Version.

References

Full note on SAP: SAP Support Launchpad note 2061519

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More