SAP Security Note
Medium priority
SAP security note 2524203, "Switchable authorization checks for RFC in SAP ERP Contract Accounts Receivable and Payable", is a note released on June 11, 2019. Below are the symptom and the SAP recommended solution.
Description
Symptom
This SAP Security Note addresses the insufficiency of S_RFC authorization checks in ensuring the secure execution of certain RFC function modules within SAP ERP Contract Accounts Receivable and Payable (FI-CA). It introduces new, switchable authorization checks designed to enhance security for these RFC function modules.
Solution
The solution involves activating the new switchable authorization checks introduced by this SAP Note. These checks are initially inactive to maintain compatibility with existing processes. To enable them:
- Implement the Switchable Authorization Checks: Use transaction SACF to configure the new authorization scenario (FKK_DOCUMENT_READ). Follow the correction instructions provided in the note to upload and transfer the scenario definitions.
- Activate the Checks: After updating your system, use transaction SACF_COMPARE to activate the switchable authorization checks. Assign the scenario definition to the appropriate development package as outlined in the manual activities section of the note.
For detailed step-by-step instructions, refer to the Implementation and Activation Guide.
Reason and prerequisites
By default, remote calls of RFC function modules are protected by checks for the authorization object S_RFC. However, these checks alone may not be sufficient for all scenarios. This note is relevant if you are using SAP Contract Accounts Receivable and Payable or its corresponding industry solutions. Ensure that the authorizations for S_RFC are restricted to the minimum required to maintain system security.
CVSS
Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
References
Full note on SAP: SAP Support Launchpad note 2524203
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
