Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Security audit on SAP Systems 1

Status
Not open for further replies.

MartinBzm

Programmer
Oct 15, 2002
3
0
0
NL
We are doing a security audit on our systems, one is a SAP FiCo 4.6C implementation. There are a few issues we have to investigate:
1. Are there known ways to gain access to the central SAP system through a terminal with a GUI installed that circumvent the login screen?
2. Is it possible for a -restricted- user to 'upgrade' his security profile so that he can access transactioncodes he should not have access to?
3. Is it possible for a -restricted- user to upload and execute ABAP programs even when he has no access to the ABAP Workbench?

And if so, how can we secure the system against these type of illegal actions?

Thanks in advance.

Free? Does that mean I can't get a Discount?
 
to 1. : No.
to 2. : No.
to 3. : No.

nothing of what u asked for is possible in a proper customized system (with proper authorisation-conception)

the real security problems are found one level below, in database access, server communication etc.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top