Search This Blog

Tuesday, August 23, 2011

SAP Note 1085326 - Security Note: Check for 'System -> Status' (SE80)

Symptom


You are logged on to an SAP system using SAP GUI. You use

    1. the menu:  System -> Status...
    2. in the F1 help (in the modal window):
      a) the F9-button or
      b) 'Technical Information' (or 'Technical info') from context menu or
      c) 'Technical Information' (or 'Technical info') button on the F1 Help screen
    3. the button 'Technical Information' in the Performance Assistant

to display technical information about the system or the current transaction. By double-clicking, you can display the selected Workbench object, although the authorization for the ABAP Workbench (transaction SE80) was not assigned to your user profile.



Other terms

S_DEVELOP, 16, SE80, RDOCFINDER, search report, SE61, worklist, RS_ACCESS_PERMISSION, AUTHORITY_CHECK_TCODE, RS_TOOL_ACCESS

Reason and Prerequisites

The system does not check transaction code SE80 (authorization object S_TCODE).

Solution

Use the Note Assistant to implement the corrections or import the relevant Support Package.

After you have implemented the corrections, a user that is not authorized to use transaction SE80 can no longer navigate from the 'Technical info'.

To check the changed function, create a user without authorization for transaction SE80 in the authorization object S_TCODE and perform the steps described under "Symptom".




Affected Releases
Software
Component
Release
From
Release
To
Release
And
subsequent
SAP_BASIS
46
46C
46C
 
SAP_BASIS
60
620
640
 
SAP_BASIS
70
700
700
 
SAP_BASIS
71
710
710
 


Visit https://service.sap.com/sap/support/notes/1085326 for Correction delivered in Support Package and Corrections Instructions

No comments:

Post a Comment