Solution : https://service.sap.com/sap/support/notes/1085326 (SAP Service marketplace login required)
Summary :
This SAP Note addresses a security issue whereby users unauthorized for ABAP Workbench (transaction SE80) can access and execute transaction SE80 when using SAP GUI to navigate technical information. The unauthorized navigation occurs through various entry points such as System Status, F1 Help, and the Performance Assistant. The root cause is a lack of proper transaction code checks for SE80 (related to authorization object S_TCODE). The resolution involves applying a correction through Note Assistant or importing a Support Package to restrict unauthorized users from navigating to transaction SE80 from the identified entry points.
Key words :
check transaction code se80, relevant support package, selected workbench object, authorization object s_tcode, button 'technical information', display technical information, transaction se80, 'technical information', abap workbench, current transaction
Related Notes :
1404965 | No navigation from "Technical Information" in SE80 |
1388729 | SE80 authorization check in RS_TOOL_ACCESS |
888889 | Automatic checks for security notes using RSECNOTE |