SAP Security Note
High priority
SAP security note 2393937, "VMC Authority Check", released on 12.11.2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This security note addresses missing authorization checks in SAP Internet Pricing and Configurator (IPC), Version AP 7.00 and higher. Specifically, IPC does not perform necessary authorization checks for authenticated users, potentially allowing escalation of privileges.
Restricted functionalities could be exploited by unauthorized user groups, with a risk of reading, modifying, or deleting restricted data.
Solution
- Support Package Installation: available from AP 7.00 SP25 to SP34 as a patch, and in standard for AP 7.00 SP35 and AP 7.50 SP06.
- Activation of Authorization Checks: use transaction SACF to activate the new authorization scenario.
- Update Roles: ensure that all roles using AP Engines have the IPC authorization object added.
Reason and prerequisites
Remote calls to RFC function modules are protected by the S_RFC authorization object by default. However, these checks might not suffice for certain RFC function modules. Activating the new switchable authorization checks is necessary for enhanced security.
CVSS
Score 7.1 Vector: CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H
References
- Note 2368820 – Signal 11 while using Java_com_sap_vmc_sec_auth_JTSAuthority_checkPermission
- Note 2316425 – Architectural change
- Note 2216306 – S_RFC check and profile parameter auth/rfc_authority_check
- Note 2008727 – Securing Remote Function Calls (RFC)
- Note 1995667 – SACF: Navigation error
- Note 1922808 – SACF | FAQ | Supplementary information about the application
Affected components
- SAP_AP: Versions 700, 750
- SAPAPIPCJ: Version 700
Full note on SAP: SAP Support Launchpad note 2393937
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



