SAP security note 1457387, "Unauthorized access to configuration data". Below are the symptom and SAP recommended solution.
Description
Symptom
The adjustment request customization tables must have restricted access.
Only authorization group CRMC should have access to the tables.
This fix is needed to block unauthorized access to important system private data.
Solution
For this correction, change the tables’ authorization group to CRMC. Follow the manual activities for the corresponding releases.
Reason and prerequisites
Security Authorization Access
Full note on SAP: SAP Support Launchpad note 1457387
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



