Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
Производитель ПО
Наименование ПО
SAP Notes
(1690942-3)
SAP Support Packages
(530_731, SAPK-10009INGRCPINW, SAPK-10109INGRCPINW, SAPK-10209INGRCPINW, SAPK-10309INGRCPINW, SAPK-10409INGRCPINW, SAPK-40012INVIRSANH, SAPK-40112INVIRSANH, SAPK-40212INVIRSANH, SAPK-40313INVIRSANH, SAPK-47013INVIRSA, SAPK-52016INVIRSANH, SAPK-52117INVIRSANH, SAPK-52217INVIRSANH, SAPK-52317INVIRSANH, SAPK-53020INVIRSANH, SAPK-53120INVIRSANH, SAPK-53220INVIRSANH, SAPK-53320INVIRSANH, SAPK-53414INVIRSANH, SAPK-V4719INVIRSA, SAPK-V4C20INVIRSA, SAPK-V4E20INVIRSA, V1000_731)
Описание
VIRSA and VIRSANH does not contain authorization checks for checking an authenticated user's authorization to access some of its functions. This may result in undesired system behavior.
Как исправить
In GRC SPM application the user exit SUSR0001 has been in use to prevent the direct login of Fire Fighter IDs into R/3 application, the include /virsa/zvirsa_userexit would take care of preventing the FFIDs from direct login. However this particular user exit can be by passed.
In order to overcome this particular security gap from user exit, an Trusted RFC concept has been implemented in SPM application.
And some of the benefits with Trusted RFC are password is not required to login via RFC whenever an FFID logins into the system.
For the trusted RFC settings, additional authorization details and Fire Fighter Role modifications please find the attachment
In order to overcome this particular security gap from user exit, an Trusted RFC concept has been implemented in SPM application.
And some of the benefits with Trusted RFC are password is not required to login via RFC whenever an FFID logins into the system.
For the trusted RFC settings, additional authorization details and Fire Fighter Role modifications please find the attachment
Ссылки