Search This Blog

Thursday, March 10, 2011

SAP Note 1357370 - No authorization check for editor

Note 1357370 - No authorization check for editor


Symptom


In some programs, you can start the editor in change mode, even though the relevant development authorization does not exist (authorization object S_DEVELOP).

However, changes made in the editor are generally not transferred to the current process; the editor call is used only to display dynamically generated ABAP or SQL.

Since you cannot always be sure that the source code that was changed using the editor is executed, the attached corrections ensure that the change authorization is always checked and that only displayed mode is chosen if the user does not have the required authorization.

Other terms

RSAPO, APO interface, RSDRU, security standard, Securitystandard

Reason and Prerequisites

This problem is caused by a program error.
Solution

After you implement the correction instructions, the development authorization is checked before the editor is opened. If it is missing, the editor is opened only in display mode.
  • SAP NetWeaver BI 7.00
           Import Support Package 22 for SAP NetWeaver BI 7. 00 (SAPKW70022) into your BI system.
  • SAP NetWeaver BI 7.01 (SAP NW BI 7.0 Enhancement Package 1)
           Import Support Package 05 for SAP NetWeaver BI 7. 01 (SAPKW70105) into your BI system.
  • SAP NetWeaver BI 7.02 (SAP NW BI 7.0 Enhancement Package 2)
           Import Support Package 02 for SAP NetWeaver BI 7. 02 (SAPKW70201) into your system.
  • SAP NetWeaver BI 7.10
           Import Support Package 08 for SAP NetWeaver BI 7. 10 (SAPKW71008) into your BI system.
  • SAP NetWeaver BI 7.11
           Import Support Package 03 for SAP NetWeaver BI 7. 11 (SAPKW71103) into your BI system.
  • BW 3.0B and BW 3.10 Content

    Implement the attached correction instructions. For SAP BW Releases 3.0B and 3.10, no additional Support Packages will be delivered until further notice.
  • BW 3.50
           Import Support Package 26 for 3.5 (BW 3. 50 Patch 26 or SAPKW35026) into your BW system.
  • BW 2.0B / BW 2.10 Content

    Implement the attached correction instructions. No additional Support Packages will be delivered for SAP BW Releases 2.0B and 2.1C.
           
In urgent cases, you can implement the correction instructions as an advance correction. You must first read Note 875986, which provides information about transaction SNOTE.



Affected Releases
Software
Component
Release
From
Release
To
Release
And
subsequent
SAP_BW
20
20B
20B
 
SAP_BW
21
21C
21C
 
SAP_BW
30
30B
30B
 
SAP_BW
310
310
310
 
SAP_BW
35
350
350
 
SAP_BW
70
700
702
 
SAP_BW
71
710
720
 
SAP_BW_VIRTUAL_COMP
30 350
30B
30B
 
SAP_BW_VIRTUAL_COMP
70 701
701
701
 

No comments:

Post a Comment