DISQUS

The BASIS of SAP: ECC6 SE16N vulnerability and logging

  • leonsteinhardt · 2 months ago
    I strongly disagree. SE16N is an essential developer tool, in all systems including production.
    SE16N is not a danger as long as authorization is display only. An attempt to use @SAP_EDIT then results in an authorization failure; the SU53 shows

    Authorization Obj. S_DEVELOP ABAP Workbench
    Object Class BC_C Basis - Development Environment
    Activity 02
    Package <Dummy>
    Object name <Dummy>
    Object type DEBUG
    Authorization group ABAP/4 program <Dummy>

    Properly structuring authorizations is the appropriate response to the potential danger - not removing the tool.