<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sensitive Transaction issue in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/sensitive-transaction-issue/m-p/7157608#M1515419</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Today we have experienced that below combination has been declared as violation in our system&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below Transactions with it's related objects&lt;/P&gt;&lt;P&gt;/VIRSA/VFAT&lt;/P&gt;&lt;P&gt;/VIRSA/ZVFAT_U02&lt;/P&gt;&lt;P&gt;/VIRSA/ZVFAT_U03&lt;/P&gt;&lt;P&gt;/VIRSA/ZVFAT_U04&lt;/P&gt;&lt;P&gt;/VIRSA/ZVFAT_V01&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Object&lt;/P&gt;&lt;P&gt;S_PROGRAM for SUBMIT for any program group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the person having access to FF transaction has access to S_PROGRAM for many other transactions via different roles. So It is impossible that we can remove any of the side to eliminate the violation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However we are thinking about mitigation. But before that we would like to know that what is risk involve for above combination of access??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arpan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Aug 2010 07:40:17 GMT</pubDate>
    <dc:creator>arpan_paik</dc:creator>
    <dc:date>2010-08-16T07:40:17Z</dc:date>
    <item>
      <title>Sensitive Transaction issue</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sensitive-transaction-issue/m-p/7157608#M1515419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Today we have experienced that below combination has been declared as violation in our system&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below Transactions with it's related objects&lt;/P&gt;&lt;P&gt;/VIRSA/VFAT&lt;/P&gt;&lt;P&gt;/VIRSA/ZVFAT_U02&lt;/P&gt;&lt;P&gt;/VIRSA/ZVFAT_U03&lt;/P&gt;&lt;P&gt;/VIRSA/ZVFAT_U04&lt;/P&gt;&lt;P&gt;/VIRSA/ZVFAT_V01&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Object&lt;/P&gt;&lt;P&gt;S_PROGRAM for SUBMIT for any program group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the person having access to FF transaction has access to S_PROGRAM for many other transactions via different roles. So It is impossible that we can remove any of the side to eliminate the violation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However we are thinking about mitigation. But before that we would like to know that what is risk involve for above combination of access??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arpan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Aug 2010 07:40:17 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sensitive-transaction-issue/m-p/7157608#M1515419</guid>
      <dc:creator>arpan_paik</dc:creator>
      <dc:date>2010-08-16T07:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: Sensitive Transaction issue</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sensitive-transaction-issue/m-p/7157609#M1515420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Arpan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our 5.1 system does not throw an error for this combination. The Virsa transactions can be limited in a separate authorization by the User Actions BTCSUBMIT, SUBMIT, VARIANT and Authorization Group ZVFAT*. That's also the default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Happy Complying,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Robert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Aug 2010 12:40:20 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sensitive-transaction-issue/m-p/7157609#M1515420</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-08-16T12:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: Sensitive Transaction issue</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sensitive-transaction-issue/m-p/7157610#M1515421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you see the default role it will not have S_Program by default&lt;/P&gt;&lt;P&gt;this should be the role which has to be assigned to users who need firefighter access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you validate which role from the list below you have assigned to users&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/VIRSA/Z_VFAT_ADMINISTRATOR	Firefighter Administrator Role with full access&lt;/P&gt;&lt;P&gt;/VIRSA/Z_VFAT_FIREFIGHTER	Firefighter Firefighter's role&lt;/P&gt;&lt;P&gt;/VIRSA/Z_VFAT_ID_OWNER	Firefighter FirefighID owner's role &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I strongly believe that you have assigned the administrator/Owners role.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best solution will be to identify the administrators and assign the admin roles only to them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure to have the following  for S_program&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User action ABAP/4 program     BTCSUBMIT, SUBMIT, VARIANT                                                  P_ACTION&lt;/P&gt;&lt;P&gt;Authorization group ABAP/4 pro ZVFAT, ZVFAT*                                                               P_GROUP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Aug 2010 17:08:55 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sensitive-transaction-issue/m-p/7157610#M1515421</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-08-16T17:08:55Z</dc:date>
    </item>
  </channel>
</rss>

