Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security note Access to RFC-enabled modules via SOAP, SAP security note 1394100

SAP Note 1394100
SAP Security Note
High priority

SAP security note 1394100, “Access to RFC-enabled modules via SOAP”, is a consulting note released on 15.10.2009. Below are the symptom, reason and prerequisites, SAP recommended solution and the related references.

ComponentBasis Components > Middleware > Internet Communication Framework
CategoryConsulting
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on15.10.2009
LanguageEnglish

Description

Symptom

The unrequired execution of remote-enabled function modules occurs via SOAP and the HTTP channel if a particular ICF service was activated incorrectly, or if the definition of an RFC authorization was not restrictive enough.

Solution

Check whether the service in your landscape is used for particular software solutions. If not, the following applies:

  • For releases higher than 610: Deactivate the service /sap/bc/soap/rfc in transaction SICF.
  • For Release 610: In the “SAP Authorization” field on the “Service Data” tab page, maintain an authorization value for the service /sap/bc/soap/rfc, to which no user in the system is assigned. For more information about this, refer to the input help of the field.

If the use of this service is not known, you can find this out by analyzing the ICMan server log, for example. When ICMan logging is activated, you will find the server log entries in transaction SMICM → Goto → HTTP Log. The documentation of the ICMan server log is on the SAP Help Portal for Release 620.

If the service /sap/bc/soap/rfc is used in your landscape for software solutions, check whether the authorizations that have been defined for the user that is used in the solution are restrictive enough.

As of Web Application Server 640 (SAP NetWeaver 2004), use the Web Service Framework. For more information about migration, see the SOAP Migration Guide 6.20 to 6.40. The migration enables dedicated activation or deactivation for each Web Service entry in the SICF transaction under /sap/bc/srt.

Reason and prerequisites

If the service /sap/bc/soap/rfc is activated in transaction SICF, it is possible to access remote-enabled function modules in the ABAP system if the user has the relevant authorizations (see Note 93254).

This may lead to a security risk for ABAP systems in internet or intranet scenarios (also see the standard passwords in Note 40689).

Also refer to Note 626073.

References

Full note on SAP: SAP Support Launchpad note 1394100

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More

Three identical server cabinets carrying stacks of code of very different heights beside a measuring rule

ABAP Code Security Scan Cost Drivers

What moves the cost of an ABAP code security scan: custom object counts, effective lines, systems in scope, transport gating, triage and retest.