Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable authorization checks for RFC in Product Catalog, SAP security note 2265385

SAP Note 2265385
SAP Security Note
Medium priority

SAP security note 2265385, "Switchable authorization checks for RFC in Product Catalog", is a program error note released on 22.12.2016. Below are the symptom, SAP recommended solution and the affected software components.

ComponentInternet Sales Catalog (CRM-ISA-CAT)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on22.12.2016
LanguageEnglish

Description

Symptom

This SAP note describes new switchable authorization checks for RFC function modules in Product Catalog.

Solution

New switchable authorization checks have been implemented. The checks are delivered inactive to ensure compatibility with your running processes. The checks can be activated in transaction SACF as described in attached manual correction instruction. See note 1922808 for additional information on the switchable authorization check framework (SACF).

  • New authorization scenario CRM_PCAT_1: Authorization Check for Product Catalogs (1).
  • Affected business process: API function modules used by different product Catalog functionalities.
  • Authorization objects used to check the proper authorization of the user: COM_PCAT and COM_PC_LOC.

Reason and prerequisites

Remote calls to RFC function modules are protected by checks on the authorization object S_RFC. Authorizations for S_RFC must be limited to the required minimum authorizations for all users to ensure system security. Many RFC function modules can be sufficiently protected using S_RFC authorization checks. These RFC function modules often do not perform additional functional authorization checks. Please see SAP note 2008727 for further information on RFC Security.

It was identified that S_RFC authorization checks might not be sufficient to ensure secure execution for RFC function modules covered by this note. Activate new switchable authorization checks and update corresponding roles if these RFC function modules are included in S_RFC authorizations in your system.

CVSS

Score 0 Vector: Not Defined

References

Affected components

  • BBPCRM 700
  • BBPCRM 701
  • BBPCRM 702
  • BBPCRM 712
  • BBPCRM 713
  • BBPCRM 714

Full note on SAP: SAP Support Launchpad note 2265385

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More