Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable authorization checks for RFC in SAP ERP Contract Accounts Receivable and Payable, SAP security note 2524203

SAP Note 2524203
SAP Security Note
Medium priority

SAP security note 2524203, "Switchable authorization checks for RFC in SAP ERP Contract Accounts Receivable and Payable", is a note released on June 11, 2019. Below are the symptom and the SAP recommended solution.

ComponentFI-CA (Financial Accounting > Contract Accounts Receivable and Payable)
PriorityMedium priority
TypeSAP Security Note
StatusReleased for Customer
Released onJune 11, 2019

Description

Symptom

This SAP Security Note addresses the insufficiency of S_RFC authorization checks in ensuring the secure execution of certain RFC function modules within SAP ERP Contract Accounts Receivable and Payable (FI-CA). It introduces new, switchable authorization checks designed to enhance security for these RFC function modules.

Solution

The solution involves activating the new switchable authorization checks introduced by this SAP Note. These checks are initially inactive to maintain compatibility with existing processes. To enable them:

  • Implement the Switchable Authorization Checks: Use transaction SACF to configure the new authorization scenario (FKK_DOCUMENT_READ). Follow the correction instructions provided in the note to upload and transfer the scenario definitions.
  • Activate the Checks: After updating your system, use transaction SACF_COMPARE to activate the switchable authorization checks. Assign the scenario definition to the appropriate development package as outlined in the manual activities section of the note.

For detailed step-by-step instructions, refer to the Implementation and Activation Guide.

Reason and prerequisites

By default, remote calls of RFC function modules are protected by checks for the authorization object S_RFC. However, these checks alone may not be sufficient for all scenarios. This note is relevant if you are using SAP Contract Accounts Receivable and Payable or its corresponding industry solutions. Ensure that the authorizations for S_RFC are restricted to the minimum required to maintain system security.

CVSS

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References

Full note on SAP: SAP Support Launchpad note 2524203

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More