SAP Security Note
Medium priority
SAP security note 2030657, "Switchable authorization checks for RFC in PSM-GPR", is a program error note released on August 1, 2018. Below are the SAP recommended solution and the affected software components.
Description
Solution
The solution involves activating the newly implemented switchable authorization checks. These checks are initially delivered in an inactive state to maintain compatibility with existing processes. Administrators should:
- Activate the new authorization checks.
- Update the corresponding user roles to incorporate the new authorization requirements.
This ensures that RFC function modules have enhanced security without disrupting current operations.
Reason and prerequisites
Remote Function Calls (RFC) to function modules are typically secured using the authorization object S_RFC. However, it has been identified that relying solely on S_RFC might not suffice for certain RFC function modules covered by this note. To address potential security gaps, new authorization checks have been developed.
- Ensure that the RFC function modules affected by this note are included in your S_RFC authorizations.
- Review SAP Note 2008727 for additional information on RFC security best practices.
Affected components
- SAP_APPL: 600, 602, 603, 604, 605, 606, 616, 617
- EA-PS: 600, 603, 604, 605, 606, 616, 617
Full note on SAP: SAP Support Launchpad note 2030657
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
