Quantcast
Channel: SCN : All Content - Security
Viewing all articles
Browse latest Browse all 2858

Display access to SE38, SE37 & SE80 in production

$
0
0


I know that these transactions have traditionally been a risk to give in a production systems, even with display only access.  However, SAP has improved authorization checks on these tcodes so that execute capability is only allowed if the user has S_DEVELOP with activity 16 and the name of the program or function module being executed.

 

Is there still a risk in giving these and if so, can you please describe them?


Viewing all articles
Browse latest Browse all 2858

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>