SAP Note 1085326 - Security Note: Check for 'System -> Status' (SE80)

Component : Documentation Tools - F1-Help

Solution : https://service.sap.com/sap/support/notes/1085326 (SAP Service marketplace login required)

Summary :
This SAP Note addresses a security issue whereby users unauthorized for ABAP Workbench (transaction SE80) can access and execute transaction SE80 when using SAP GUI to navigate technical information. The unauthorized navigation occurs through various entry points such as System Status, F1 Help, and the Performance Assistant. The root cause is a lack of proper transaction code checks for SE80 (related to authorization object S_TCODE). The resolution involves applying a correction through Note Assistant or importing a Support Package to restrict unauthorized users from navigating to transaction SE80 from the identified entry points.

Key words :
check transaction code se80, relevant support package, selected workbench object, authorization object s_tcode, button 'technical information', display technical information, transaction se80, 'technical information', abap workbench, current transaction

Related Notes :

1404965No navigation from "Technical Information" in SE80
1388729SE80 authorization check in RS_TOOL_ACCESS
888889Automatic checks for security notes using RSECNOTE