Search This Blog

Tuesday, August 23, 2011

SAP Note 1168813 - Security note: Program DISPLAY_FUNC_INCLUDE


Symptom
The program DISPLAY_FUNC_INCLUDE does not have an authorization check.


Other terms
Security, SE37, Function Builder


Reason and Prerequisites
You can use the program DISPLAY_FUNC_INCLUDE as an alternative, restricted editor for function module includes.


Solution
A developer authorization check and a check for the changeability of the system can be included in the program. Implement the attached correction instructions.
The program is deleted with the Support Packages specified in this note.
The corrections do not influence the normal functioning of the application.
We strongly recommend that you implement this note to eliminate this security flaw.


Affected Releases
Software
Component
Release
From
Release
To
Release
And
subsequent
SAP_BASIS
70
700
700
 
SAP_BASIS
71
710
710
 

Correction delivered in Support Package
Support
Packages
Release
Package
Name
SAP_BASIS
700
SAP_BASIS
710

Corrections Instructions
Correction
Instruction
Valid
from
Valid
to
Software
Component
Last
Modifcation
700
700
SAP_BASIS
13.05.2008  09:22:17
710
710
SAP_BASIS
13.05.2008  09:00:58

No comments:

Post a Comment