SAP Knowledge Base Article - Preview

3674801 - FAQ for SAP Security Note 3623440 - [CVE-2025-42953] Missing Authorization check in SAP NetWeaver Application Server for ABAP

Symptom

  • Implementation of SAP security note 3623440 requires additional authorization checks for accessing the functional module RZL_CLEAR_ALL_BA.
  • Users without the S_RZL_ADM authorization will be unable to execute the functional module or modify operation modes.
  • The functional module RZL_CLEAR_ALL_BA is relevant for operation modes (transaction codes RZ03 and RZ04) but is not relevant for business processes.


Read more...

Environment

  • SAP NetWeaver
  • SAP NetWeaver Application Server for SAP S/4HANA
  • ABAP PLATFORM - Application Server ABAP

Product

ABAP platform all versions ; SAP NetWeaver all versions ; SAP Web Application Server for SAP S/4HANA all versions

Keywords

authorization check, functional module, rz03, rz04, operation modes, sap security note, S_RZL_ADM, RZL_CLEAR_ALL_BA, implementation, authorization, restriction, SAP NetWeaver , KBA , BC-CCM-CNF-OPM , Operation Modes , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.