SAP security note 2059285, “Switchable authorization checks for RFC in LO-MD-BP-CM”, is a note. Below is the security information published by SAP for this note.
Description
This SAP Security Note introduces new switchable authorization checks for RFC function modules within the LO-MD-BP-CM component. These enhancements aim to strengthen the security measures by ensuring that remote function calls are adequately authorized.
Symptom
The existing S_RFC authorization checks may not be sufficient to guarantee the secure execution of certain RFC function modules. This vulnerability necessitates the implementation of additional authorization controls to enhance system security.
Solution
New switchable authorization checks have been implemented and are delivered in an inactive state to maintain compatibility with existing processes. These checks can be activated manually using transaction SACF. Below are the steps to activate these authorization checks:
References
Full note on SAP: SAP Support Launchpad note 2059285
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



