Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable Authorization checks for SAP ERP, SAP security note 2527346

SAP Note 2527346

SAP security note 2527346, "Switchable Authorization checks for SAP ERP". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Security Note 2527346 addresses the insufficiency of S_RFC authorization checks for securing the execution of RFC function modules in Records Management and Guaranteed Minimum. This note introduces new switchable authorization checks that enhance system security by allowing these checks to be activated as needed.

Solution

New authorization scenarios are implemented but remain inactive by default to ensure compatibility. Activation can be performed via transaction SACF.

  • Part 1: Creation of Scenario Definitions – Execute the report /SAPPSPRO/NOTE_2527346 using transaction SE38.
  • Part 2: Creating Productive Authorization Scenarios – Use transaction SACF to transfer scenario definitions to productive scenarios. Choose the status Active to enforce authorization checks or Logging to monitor without enforcing.
  • Part 3: Activate Logging – Ensure Security Audit Log is activated in transaction SM19. Activate message IDs DUO, DUP, and DUQ for detailed logging.
  • Part 4: Adjust User Roles – Identify and assign necessary authorizations to users based on audit logs using report RSAU_SELECT_EVENTS.

CVSS

Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

References

Affected components

  • SAP_APPL (Releases 600 to 618)
  • S4CORE (Releases 100 to 102)
  • SAP_BASIS (Various Releases)

Full note on SAP: SAP Support Launchpad note 2527346

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More