Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Encrypting credit card data, SAP security note 633462

SAP Note 633462
SAP Security Note
Low priority

SAP security note 633462, “Encrypting credit card data”, is a legal change note released on 08.10.2009. Below are the symptom, reason and prerequisites, SAP recommended solution and references.

ComponentSales and Distribution > Billing > Processing Billing Documents > Payment Cards (SD-BIL-IV-PC)
CategoryLegal change
PriorityCorrection with low priority
TypeSAP Security Note
Version7
StatusReleased for Customer
Released on08.10.2009
LanguageEnglish

Description

Symptom

For legal reasons, you must save payment card numbers to a database in encrypted form. Before you activate the encryption function, refer to the FAQ contained in Note 766703.

Solution

To activate encryption, your system must meet the following requirements:

  • For Release 4.6C, you must import Support Package SAPKH46C46.
  • Kernel 4.6D must have patch level 1329 (see Note 565111).
  • For Release 470, you must import Support Package SAPKH47022.
  • For Release ERP 500, you must import Support Package SAPKH50007.
  • Download and install SAPCRYPTOLIB (see Note 662340). You must use the CCARD application when you use Transaction SSFA to set up encryption.

Activation steps:

  • Start the SAPFACCG report once.
  • Depending on the card type, use Transaction SM30 to activate encryption. Maintain the CCARDEC_V view.
  • Use the CCARDEC_CHECK report to ensure that the encryption tool is working correctly. Only select the P_TOOLS checkbox and then execute the report on all application servers.
  • If encryption works correctly (Process Encryption/Decryption passed), you can start to convert existing data. This is only necessary if you also want to encrypt legacy data. Two reports (first CCARDEC_TRANSFORM_SD and then CCARDEC_TRANSFORM_FI) are used to convert the data.
  • Data conversion using the CCARDEC_TRANSFORM_SD report takes place in two steps: start the report and choose the action ‘Encrypt’ (the credit card number is encrypted and saved to the database), then start the report and choose the action ‘Check’ (the encrypted payment card number is checked and the original payment card number is masked). For testing purposes, you can carry out both steps without performing a database update (by setting the test indicator to ‘X’).
  • Then carry out the same steps using the CCARDEC_TRANSFORM_FI report.
WarningThe required corrections can only be delivered in a Support Package.

Reason and prerequisites

This is a legal requirement.

References

Full note on SAP: SAP Support Launchpad note 633462

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More