<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SE38 Authorization in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/se38-authorization/m-p/12600509#M2010968</link>
    <description>&lt;P&gt;There is no link between SE38 transaction and SUBMIT statement. &lt;/P&gt;&lt;P&gt;SE38 must be removed from production system (and SE37, SE24, SE80, ....)&lt;/P&gt;</description>
    <pubDate>Mon, 12 Sep 2022 06:42:28 GMT</pubDate>
    <dc:creator>FredericGirod</dc:creator>
    <dc:date>2022-09-12T06:42:28Z</dc:date>
    <item>
      <title>SE38 Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/se38-authorization/m-p/12600508#M2010967</link>
      <description>&lt;P&gt;Dear All&lt;/P&gt;
  &lt;P&gt;Kindly help me on this doubt&lt;/P&gt;
  &lt;P&gt;We are planning to remove SE38 access to all the users in production. &lt;/P&gt;
  &lt;P&gt;However, many of our Programs using SUBMIT statments inside the custom z-programs. &lt;/P&gt;
  &lt;P&gt;Hence, removing SE38 access - do they have impact on these SUBMIT statements being executed or interrupted.&lt;/P&gt;
  &lt;P&gt;Kindly help&lt;/P&gt;
  &lt;P&gt;regards,Venkat&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 06:25:16 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/se38-authorization/m-p/12600508#M2010967</guid>
      <dc:creator>venkateswaran_k</dc:creator>
      <dc:date>2022-09-12T06:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: SE38 Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/se38-authorization/m-p/12600509#M2010968</link>
      <description>&lt;P&gt;There is no link between SE38 transaction and SUBMIT statement. &lt;/P&gt;&lt;P&gt;SE38 must be removed from production system (and SE37, SE24, SE80, ....)&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 06:42:28 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/se38-authorization/m-p/12600509#M2010968</guid>
      <dc:creator>FredericGirod</dc:creator>
      <dc:date>2022-09-12T06:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: SE38 Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/se38-authorization/m-p/12600510#M2010969</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;I don't fully agree to your last statement. For end users: yes. But I think for the IT support the access to these transactions IMHO should be given, otherwise you make their work more difficult. If you want to avoid people executing any program, you can do this by removing S_DEVELOP with Activity 16.&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Jan&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 07:02:42 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/se38-authorization/m-p/12600510#M2010969</guid>
      <dc:creator>jmodaal</dc:creator>
      <dc:date>2022-09-12T07:02:42Z</dc:date>
    </item>
    <item>
      <title>Re: SE38 Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/se38-authorization/m-p/12600511#M2010970</link>
      <description>&lt;P&gt;program execution access if not via  transaction code should be SA38 with S_PROGNAM/S_PROGRAM which then has the SUBMIT, BTCSUBMIT, etc. Transaction SE38 for code uses the S_DEVELOP&lt;/P&gt;&lt;P&gt;I find the backdoor - admins take away SE38 but leave SA38 with S_PROGRAM wide open &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 07:30:57 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/se38-authorization/m-p/12600511#M2010970</guid>
      <dc:creator>Colleen</dc:creator>
      <dc:date>2022-09-12T07:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: SE38 Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/se38-authorization/m-p/12600512#M2010971</link>
      <description>&lt;P&gt;&lt;SPAN class="mention-scrubbed"&gt;jmodaal&lt;/SPAN&gt; you have to chose between security and confort.&lt;/P&gt;&lt;P&gt;A production system should not be used by IT, there is no good reason to run SE38 transaction. &lt;/P&gt;&lt;P&gt;There is the solution of the Firefighter (in GRC) to give quickly a temporary role with a lot of authorization. You could recreate it with specific development in your system.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 07:37:01 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/se38-authorization/m-p/12600512#M2010971</guid>
      <dc:creator>FredericGirod</dc:creator>
      <dc:date>2022-09-12T07:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: SE38 Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/se38-authorization/m-p/12600513#M2010972</link>
      <description>&lt;P&gt;To be precise about what you say "removing SE38 access", I guess you mean "removing authorization with object = S_TCODE and TCD = SE38".&lt;/P&gt;&lt;P&gt;SUBMIT does not check this authorization as you can see in the ABAP doc, and you can check by doing an authorization trace. &lt;A href="https://help.sap.com/doc/abapdocu_latest_index_htm/latest/en-US/index.htm?file=abapsubmit.htm"&gt;ABAP doc SUBMIT&lt;/A&gt;: &lt;I&gt;"When the statement SUBMIT is executed, an authorization check for the authorization group specified in the program attributes is performed using the authorization object S_PROGRAM. The program attribute Start Using Variant is ignored in SUBMIT."&lt;/I&gt; (you can deduce that there is no other authorization check)&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 07:41:39 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/se38-authorization/m-p/12600513#M2010972</guid>
      <dc:creator>Sandra_Rossi</dc:creator>
      <dc:date>2022-09-12T07:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: SE38 Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/se38-authorization/m-p/12600514#M2010973</link>
      <description>&lt;P&gt;Sometimes it's a choice between security and having a functioning system. But yes - FF and other (better) solutions are available for these scenarios. &lt;/P&gt;&lt;P&gt;And then they took FF access away from IT in production... &lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 07:49:23 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/se38-authorization/m-p/12600514#M2010973</guid>
      <dc:creator>matt</dc:creator>
      <dc:date>2022-09-12T07:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: SE38 Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/se38-authorization/m-p/12600515#M2010974</link>
      <description>&lt;P&gt;Hello &lt;SPAN class="mention-scrubbed"&gt;frdric.girod&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;I see your point, however, I think it is a little bit theoretical and does not fit for everyone. Not every customer uses FireFighter. &lt;/P&gt;&lt;P&gt;I know of big SAP customers having the IT support staff on their productive systems with dedicated, restricted roles. FireFighter is also in use, but for emergency situations only. But of course the scenario you mentioned is also present.&lt;/P&gt;&lt;P&gt;With S_DEVELOP / Activity 03 (Display) only I do not see any reason why SE38 and similars are to be banned.&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Jan&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 07:54:24 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/se38-authorization/m-p/12600515#M2010974</guid>
      <dc:creator>jmodaal</dc:creator>
      <dc:date>2022-09-12T07:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: SE38 Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/se38-authorization/m-p/12600516#M2010975</link>
      <description>&lt;P&gt;The submit statement &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Doesn't require to be allowed to SE38 or SA38 (S_TCODE)&lt;/LI&gt;&lt;LI&gt;The  only authorization check performed checks the authorization group specified in the program attributes, it is performed using the authorization object &lt;A href="https://help.sap.com/doc/abapdocu_latest_index_htm/latest/en-US/index.htm?file=abapsubmit.htm"&gt;S_PROGRAM&lt;/A&gt;. There is no check if the program isn't assigned to an authorization group.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 12 Sep 2022 07:54:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/se38-authorization/m-p/12600516#M2010975</guid>
      <dc:creator>RaymondGiuseppi</dc:creator>
      <dc:date>2022-09-12T07:54:38Z</dc:date>
    </item>
  </channel>
</rss>

