SAP security note 2030357, “Switchable authorization checks for RFC in Material Version”, is a program error note released on 10.11.2014. Below is the security information published by SAP for this note.
Description
Symptom
This SAP note introduces new switchable authorization checks for RFC function modules in Material Version.
Reason and prerequisites
Remote calls to RFC function modules are currently protected by the authorization object S_RFC. However, S_RFC alone may not sufficiently secure certain RFC function modules. This note addresses these gaps by activating new switchable authorization checks. It is essential to update corresponding roles if these RFC function modules are included in your S_RFC authorizations to ensure system security.
## Solution
New switchable authorization checks have been implemented and are delivered in an inactive state to maintain compatibility with existing processes. These checks can be activated using transaction SACF as outlined in the manual correction instructions.
Full note on SAP: SAP Support Launchpad note 2030357
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
