SAP security note 2100926, "Switchable Authorization Checks for RFC in SEM-BCS". Below are the symptom and SAP recommended solution.
Description
Symptom
Remote calls to RFC function modules are currently protected by the S_RFC authorization object. However, S_RFC alone may not suffice to ensure secure execution for certain RFC function modules within SEM-BCS. This gap necessitates the activation of additional authorization checks.
Solution
The SAP Note implements new switchable authorization checks that are initially inactive to maintain compatibility with existing processes. These checks can be activated using transaction SACF. Detailed steps for activation are provided in the manual correction instructions included with the note.
References
Full note on SAP: SAP Support Launchpad note 2100926
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
