SAP Security Note
HotNews
SAP security note 1161689, "Security note: aco_bsp_admin: Start only with ICF auth.", is a program error note released on December 4, 2009. Below are the symptom, SAP recommended solution and references.
Description
Symptom
You want the BSP application aco_bsp_admin to be called only by users that have ICF authorization.
Solution
Import the Support Package relevant for your release or carry out the following manual steps:
- Call transaction SICF.
- Choose F8 for the hierarchy type "Service".
- Expand the path: default_host -> sap -> bc -> bsp -> sap.
- Double-click the service aco_bsp_admin. On the "Service Data" tab page, maintain "CHECK" under SAP authorization and save your change.
- Implement the attached correction instructions.
Reason and prerequisites
This problem is caused by a program error.
References
- 1176401 – Security: CPROJECTS_AUTH_ADMIN start only with ICF auth.
- 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Full note on SAP: SAP Support Launchpad note 1161689
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
