Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable authorization checks for RFC in SAP CRM (MSE R3-EDITION ), SAP security note 2539437

SAP Note 2539437
SAP Security Note

SAP security note 2539437, “Switchable authorization checks for RFC in SAP CRM (MSE R3-EDITION )”, is a note released on June 8, 2020. Below are the symptom and SAP recommended solution.

ComponentCRM-MSE (Customer Relationship Management > Mobile Service)
TypeSAP Security Note
Released onJune 8, 2020

Description

Symptom

Remote calls to RFC function modules in the CRM MSE Mobile solution (R3 Edition) were protected only by the S_RFC authorization object. It was identified that these checks might not be sufficient for certain RFC function modules, which could allow calls without adequate functional authorization checks.

Solution

New switchable authorization checks have been implemented for RFC function modules used in CRM reports within the CRM MSE Mobile solution (R3 Edition). The new checks are delivered inactive to ensure compatibility and require manual activation via transaction SACF.

Affected function modules:

  • CRM_CS_API_ORDER_CREATE
  • CRS_CONF_CREATE_TIMECONF
  • CRS_NOTIF_UPLOAD_CHANGE_PROXY
  • CRS_NOTIF_UPLOAD_PROXY
  • CRS_SM_CONF_UPLOAD_PROXY
  • CRS_SORDER_CREATE_UPLOAD_PROXY
  • ICSM_WORKCENTER_READ_MULTIPLE

Use transaction SACF to activate the new switchable authorization checks, following the manual correction instructions attached to the note. Perform the manual activities separately in each system where the note is transported, creating a productive authorization scenario from the scenario definition.

CVSS

Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Full note on SAP: SAP Support Launchpad note 2539437

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More