SAP Security Note
Medium priority
SAP security note 2072357, "Switchable authorization checks for RFC in SRM application.", is a program error note released on 12.05.2015. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This SAP note introduces new switchable authorization checks for RFC (Remote Function Call) function modules within the Supplier Relationship Management (SRM) application. The enhanced security measures ensure that remote calls to RFC function modules are protected by additional authorization checks beyond the standard S_RFC object. This helps in limiting user authorizations to the minimum required, thereby strengthening system security.
Solution
New switchable authorization checks have been implemented and are delivered in an inactive state to maintain compatibility with existing processes. To activate these checks, follow the steps below using transaction SACF:
- Create authorization scenario definitions: ensure that the following scenarios exist in SACF: BBP_UPDATE_DOC, BBP_DOC_CREATE, BBP_VEND_UPADTE, BBP_CONF_GETDETAIL, BBP_CTR_GETDETAIL, BBP_INV_GETDETAIL, BBP_VL_GETDETAIL. If not present, download and upload the SACF_DATA.TXT attachment.
- Activate productive authorization scenarios: transfer scenario definitions to productive scenarios. Set the status to Active to enable authorization checks and logging, or Logging to only enable logging without enforcing checks.
- Update authorization defaults: upload authorization default values using the SU22DATA.TXT file via transaction SU22 to ensure all necessary authorizations are in place.
- Adjust user roles: modify roles to include the new authorizations required by the activated scenarios.
Affected components
- SRM_SERVER (700, 701, 702, 713)
Full note on SAP: SAP Support Launchpad note 2072357
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




