<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>The BASIS of SAP - Latest Comments in ECC6 SE16N vulnerability and logging &amp;#8211; UPDATED</title><link>http://basissap.disqus.com/</link><description>Where to come to when they tell you its a BASIS problem</description><atom:link href="https://basissap.disqus.com/ecc6_se16n_vulnerability_and_logging/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Tue, 13 Oct 2009 09:51:48 -0000</lastBuildDate><item><title>Re: ECC6 SE16N vulnerability and logging &amp;#8211; UPDATED</title><link>http://www.basissap.com/2009/10/ecc6-se16n-vulnerability-and-logging/#comment-19966714</link><description>&lt;p&gt;I strongly disagree.  SE16N is an essential developer tool, in all systems including production.&lt;br&gt;SE16N is not a danger as long as authorization is display only.  An attempt to use @SAP_EDIT then results in an authorization failure; the SU53 shows&lt;/p&gt;&lt;p&gt;Authorization Obj. S_DEVELOP   ABAP Workbench&lt;br&gt;    Object Class BC_C Basis - Development Environment&lt;br&gt;         Activity                                                   02&lt;br&gt;         Package                                                  &amp;lt;dummy&amp;gt;&lt;br&gt;         Object name                                           &amp;lt;dummy&amp;gt;&lt;br&gt;         Object type                                              DEBUG&lt;br&gt;         Authorization group ABAP/4 program     &amp;lt;dummy&amp;gt;&lt;/p&gt;&lt;p&gt;Properly structuring authorizations is the appropriate response to the potential danger - not removing the tool.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">leonsteinhardt</dc:creator><pubDate>Tue, 13 Oct 2009 09:51:48 -0000</pubDate></item></channel></rss>