Search This Blog

Tuesday, March 15, 2011

SAP Note 26909 - SE16 - Security

Validity: valid since 12.03.2010


Symptom

It is uncertain which authorizations a user must have to display table contents via transaction SE16, or which authorizations the user may not have if the display of certain table contents (to this user) is to be blocked.


Other terms
EUNOTE, SE16, SE17, S_TABU_DIS, Authorization


Solution
When displaying table contents with the transaction SE16, S_TABU_DIS is checked against the authorization object.
To display a table, the user must have the display authorization (activity 03) for the authorization group of the respective table.
The authorization group comes from table TDDAT. Several tables can be grouped together in authorization groups.
If the table to be displayed is not entered in TDDAT, it is assigned to the standard authorization group "&NC&".
Thus, users who may not display any table contents should have no authorization for S_TABU_DIS. Users who should see only certain table contents should have authorization for S_TABU_DIS for a certain group only. All tables which the user may see must then be allocated to this group.

No comments:

Post a Comment