Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable authorization checks for RFC in SD, SAP security note 2066023

SAP Note 2066023

SAP security note 2066023, "Switchable Authorization Checks for RFC in SD", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The standard S_RFC authorization checks may not adequately secure certain RFC function modules used in Price Catalog Outbound, potentially allowing unauthorized access or actions through these RFC calls.

Solution

The note provides new switchable authorization checks, which are initially inactive to maintain system compatibility. Administrators need to manually activate these checks using transaction SACF by following the detailed instructions outlined in the note.

  • Activate Switchable Authorization Checks: follow the Manual Activities section in the note to upload authorization scenario definitions via transaction SACF. Create productive authorization scenarios and activate them in either "Active" or "Logging" mode.
  • Adjust User Roles: after activation, update user roles to include the necessary authorizations as specified by the new authorization scenarios.

References

Affected components

  • SAP_APPL (versions 600, 602, 603, 604, 605, 606, 616, 617)
  • EA-RETAIL (versions 600, 602, 603, 604, 605, 606, 616, 617)

Full note on SAP: SAP Support Launchpad note 2066023

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More