<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Secure custom developer programs and transactions in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491303#M1256609</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;I am given a task in my company to maintain authority check for all costom developed programs and transaction. &lt;/P&gt;&lt;P&gt;In combination TADIR, TRDIR &amp;amp; TSTC i found more then 1000 transactions and 1500 programs custom developed.&lt;/P&gt;&lt;P&gt;So now I am having difficulty in finding authority check at program level for all the custom programs and transactions. I tried to use RSABAPSC but this gives for each program/ transaction.&lt;/P&gt;&lt;P&gt;Can you guys help me to find a best way to get the list for the whol transactions and good approach to complete the task at ace and good way. &lt;/P&gt;&lt;P&gt;Please comment your best practices and approaches for this. &lt;/P&gt;&lt;P&gt;Let me know if you guys need any more information from me to make the above more clear. &lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 26 Apr 2009 10:29:02 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2009-04-26T10:29:02Z</dc:date>
    <item>
      <title>Secure custom developer programs and transactions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491303#M1256609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;I am given a task in my company to maintain authority check for all costom developed programs and transaction. &lt;/P&gt;&lt;P&gt;In combination TADIR, TRDIR &amp;amp; TSTC i found more then 1000 transactions and 1500 programs custom developed.&lt;/P&gt;&lt;P&gt;So now I am having difficulty in finding authority check at program level for all the custom programs and transactions. I tried to use RSABAPSC but this gives for each program/ transaction.&lt;/P&gt;&lt;P&gt;Can you guys help me to find a best way to get the list for the whol transactions and good approach to complete the task at ace and good way. &lt;/P&gt;&lt;P&gt;Please comment your best practices and approaches for this. &lt;/P&gt;&lt;P&gt;Let me know if you guys need any more information from me to make the above more clear. &lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Apr 2009 10:29:02 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491303#M1256609</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-04-26T10:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: Secure custom developer programs and transactions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491304#M1256610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; I am given a task in my company to maintain authority check for all costom developed programs and transaction. &lt;/P&gt;&lt;P&gt;Are we talking about SU24 or actually coding new checks into the software?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Apr 2009 11:08:36 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491304#M1256610</guid>
      <dc:creator>jurjen_heeck</dc:creator>
      <dc:date>2009-04-26T11:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: Secure custom developer programs and transactions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491305#M1256611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I first have to check at program level and then after all the programs/transactions are checked at program then I have to maintain the same at SU24 level. &lt;/P&gt;&lt;P&gt;Hope this is what you are looking for.&lt;/P&gt;&lt;P&gt;Thanks....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Apr 2009 11:14:04 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491305#M1256611</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-04-26T11:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: Secure custom developer programs and transactions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491306#M1256612</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I beleive we can execute only one Tcode/Program/Report at once.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Apr 2009 01:44:27 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491306#M1256612</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-04-27T01:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: Secure custom developer programs and transactions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491307#M1256613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Hari for your reply, but this is not going to help as its going to take me ages to look for one by one. Can someone let me know if anyone have done this task in their companies and if yes please let me know the best and good way to accomplish this task.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Apr 2009 03:46:14 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491307#M1256613</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-04-27T03:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: Secure custom developer programs and transactions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491308#M1256614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;You can use the t code suim -&amp;gt; user-&amp;gt; with complex criteria then go wid objects you are looking for . &lt;/P&gt;&lt;P&gt;it will display allin to the particular object been carried out. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;Shilpa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Apr 2009 04:48:57 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491308#M1256614</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-04-27T04:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Secure custom developer programs and transactions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491309#M1256615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shilpa,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But Amit is not looking for the users list...where as he is looking for list of authorization objects  which are part Authority check statements of customized Tcodes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Probably ABAP programmers would help us here!!!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hari&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Apr 2009 04:56:05 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491309#M1256615</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-04-27T04:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: Secure custom developer programs and transactions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491310#M1256616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not think you will find any relevant standard report/functionality in the SAP System, that could scan your Z-Report and find out if it's correctly secured with authorizations checks. Many of those checks could hide in called functionmodules, Methods etc. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And you still have need to define and check each SAP report for your companies specific security requirement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With 1000/1500 Z-transactions/reports, my guess is, that a lot of them might be obsolete, never used, temp programs for dataloads etc. So mayby you do not have to focus on all of them, so I think that my approach would be, to try to limit the number of report that I needed to investigate thoroughly, and then take the reports one by one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The steps involved would be something like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Find out which of your Z-reports/T-codes thats actually used. You should be able to se that in SM20(if you have activated the secure audit log with the correct filters), ST03N etc. Report/T-codes that are not used could be locked in SM01.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Investigate the used reports one by one, Check the Source-Code, do an Authorisation trace etc - &lt;EM&gt;Remember that if your Z-Report used BAPI and other SAP Standard functionality, Or if i reads from at DATASET etc.. you might not be able to spot the Authority-check statement in your source code&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Implement and test the relevant and requirered additional authorization check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. Document in SU24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5. Adjust the roles&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And your ready for test.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And yes I know,,,  It can be a hugh job, but I do not think that you can find a quick-fix for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Morten Nielsen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Apr 2009 06:07:54 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491310#M1256616</guid>
      <dc:creator>morten_nielsen</dc:creator>
      <dc:date>2009-04-27T06:07:54Z</dc:date>
    </item>
    <item>
      <title>Re: Secure custom developer programs and transactions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491311#M1256617</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would recommend first taking to the development co-ordinator or manager to find out whether there is any concept which the developers were meant to adhere to (e.g. program auth groups, checking tcode authority in the coding, using BAPI's, etc).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It might be more possible to scan for exceptions to the development guidelines instead of going through each program manually to start with - take a look at transaction SCI (SAP Code Inspector).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way you can prioritize to some extent and find conceptual inconsistencies - but ultimately you will need some ABAP knowledge to complete the task and go through each one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Apr 2009 09:48:25 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491311#M1256617</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-04-27T09:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: Secure custom developer programs and transactions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491312#M1256618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Morten &amp;amp; Julius for your valuable suggestions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appreciate for the procedures given to me by Morten, but this is a usual procedure which I thought of doing from day-1, but after I started the work; I am feeling that I would not be able to achieve the task by going one-one and would not be able to complete this task by the dead line. &lt;/P&gt;&lt;P&gt;But I will definitely follow your from step 2 to 5.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julius, as you have suggested I have met my ABAP lead and got some updates abt the procedures they follow during the custom developments. Here I find they donu2019t follow maintaining custom programs in program auth groups and they only maintain with authority checks and each custom report would be executed by using a custom transaction. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know the implications when we only maintain authority checks and not maintain the custom programs in program auth groups. I know is we cannot secure access in S_DEVELOP &amp;amp; S_PROGRAM. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julius: I am not very familiar with transaction SCI (SAP Code Inspector) and I tried to find come documents to know more about this, but I am failed to find something which can help my work.&lt;/P&gt;&lt;P&gt;Would appreciate if you can let me know something more on this and how it can be used in my scenariou2026. &lt;/P&gt;&lt;P&gt;Thanks for all your replies, I would appreciate if I can know more best practices on this regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Apr 2009 04:08:10 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491312#M1256618</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-04-29T04:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: Secure custom developer programs and transactions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491313#M1256619</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In addition to the described manual methods in this thread to analyse authorization checks in programs, there exist another option based on tracing, too:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Set profile parameter auth/authorization_trace as described in note [543164|https://service.sap.com/sap/support/notes/543164] and view the result using transaction SU22 (yes, in this case it't SU22).&lt;/P&gt;&lt;P&gt;Limitation (in addition to the disclaimer as described in the note): The results are quite fine for transactions and some other service types but not for reports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Frank Buchholz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S. Please keep in mind that RSABAPSC is somehow outdated - it's quite valuable for old programs respective simple programming techniques, however, it might fail if you analyse modern programs which are based on object oriented code.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Apr 2009 11:28:21 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491313#M1256619</guid>
      <dc:creator>Frank_Buchholz</dc:creator>
      <dc:date>2009-04-29T11:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Secure custom developer programs and transactions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491314#M1256620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you know the [Secure Programming |https://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/334929d6-0a01-0010-45a9-8015f3951d1a] development guide at &lt;A href="https://www.sdn.sap.com/irj/sdn/security" target="test_blank"&gt;https://www.sdn.sap.com/irj/sdn/security&lt;/A&gt; ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Well, it doesn't describe how to analyze programs for authorization checks, but contains valuable information about other areas of secure programming in ABAP and Java.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Frank Buchholz on Apr 29, 2009 1:31 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Apr 2009 11:30:48 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491314#M1256620</guid>
      <dc:creator>Frank_Buchholz</dc:creator>
      <dc:date>2009-04-29T11:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: Secure custom developer programs and transactions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491315#M1256621</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi People,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I please expect some more possible ways to approach my task as mentioned in my replies. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 May 2009 04:37:48 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491315#M1256621</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-05-04T04:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: Secure custom developer programs and transactions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491316#M1256622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The tcode and program group only are blunt tools for security, and will not let you achieve granular security nor differentiate in a meaningfull way between org levels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go for the correct and consistent authorization checks in the programs - it is the better option for maintaining a consistent role authorization concept.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you did not find information on SCI then you did not look very hard...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just search here in SDN or start transaction SCI - there is a little &lt;SPAN __default_attr="blue" __jive_macro_name="color"&gt;blue&lt;/SPAN&gt; "Information" button at the top. It will tell you what you need to know...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 May 2009 08:17:23 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491316#M1256622</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-05-04T08:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: Secure custom developer programs and transactions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491317#M1256623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Amit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have developed a security scanner for ABAP that can (among many other things) identify all authority checks in custom ABAP code. Even better - it can identify missing authority checks, too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you want to know more.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Markus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 May 2009 12:48:53 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491317#M1256623</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-05-04T12:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: Secure custom developer programs and transactions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491318#M1256624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Markus,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response, and we also have developed a custom program to read authority checks in all reports but it wont identify missing authority checks. So, can you please let me know how your program will help to show the missing authority checks.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 May 2009 07:22:29 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491318#M1256624</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-05-06T07:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: Secure custom developer programs and transactions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491319#M1256625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where can we get this Scanner and how is it different to RSABAPSC ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;Denis&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jun 2010 10:03:55 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491319#M1256625</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-06-04T10:03:55Z</dc:date>
    </item>
    <item>
      <title>Re: Secure custom developer programs and transactions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491320#M1256626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is a commercially available product. See &lt;A href="https://community.sap.com/www.virtualforge.de" target="test_blank"&gt;www.virtualforge.de&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The main difference is that it does not only scan for static coding statements, but can verify where the input is coming from and validations in between (such as authity-checks).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are several tools which do this for webservers and Java applications, but not many for ABAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jun 2010 10:37:48 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/secure-custom-developer-programs-and-transactions/m-p/5491320#M1256626</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-06-04T10:37:48Z</dc:date>
    </item>
  </channel>
</rss>

