<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAP R/3 security problem in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-r-3-security-problem/m-p/2252851#M487316</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Additional you should activate the Security Audit Log for these Super-User with Transaction SM18-SM19.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gruß&lt;/P&gt;&lt;P&gt;Toni&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 14 May 2007 09:29:07 GMT</pubDate>
    <dc:creator>antonio_steinhuser</dc:creator>
    <dc:date>2007-05-14T09:29:07Z</dc:date>
    <item>
      <title>SAP R/3 security problem</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-r-3-security-problem/m-p/2252849#M487314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is clear that the security will happen when you dropped the normal &amp;#147;SAP&lt;STRONG&gt;&amp;#148; &amp;amp; &amp;#147;DDIC&amp;#148; account because the reserved SUPER account with password "PASS" will activate. So, while you lost the normal &amp;#147;SAP&lt;/STRONG&gt;&amp;#148; &amp;amp; &amp;#147;DDIC&amp;#148; account, you should notice others people and re-create that as soon as possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to fix the security problem?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 May 2007 09:49:57 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-r-3-security-problem/m-p/2252849#M487314</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-05-12T09:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: SAP R/3 security problem</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-r-3-security-problem/m-p/2252850#M487315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you delete DDIC user then it will stay deleted.  It will not recreate itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As SAP* is a hardcoded user, if you delete it, it will recreate itself with a commonly known password.  To prevent this, you need to set profile parameter (via RZ10) login/no_automatic_user_sap* = 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will stop SAP* automatically creating itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are a number of other things you should do to restrict SAP*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Change default password&lt;/P&gt;&lt;P&gt;Lock the ID&lt;/P&gt;&lt;P&gt;Remove all profiles (SAP_ALL, SAP_NEW)&lt;/P&gt;&lt;P&gt;Assign to group SUPER&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DDIC should also have the password changed from default and be locked when it's not being used.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 May 2007 19:09:03 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-r-3-security-problem/m-p/2252850#M487315</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-05-13T19:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: SAP R/3 security problem</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-r-3-security-problem/m-p/2252851#M487316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Additional you should activate the Security Audit Log for these Super-User with Transaction SM18-SM19.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gruß&lt;/P&gt;&lt;P&gt;Toni&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2007 09:29:07 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-r-3-security-problem/m-p/2252851#M487316</guid>
      <dc:creator>antonio_steinhuser</dc:creator>
      <dc:date>2007-05-14T09:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: SAP R/3 security problem</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-r-3-security-problem/m-p/2252852#M487317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt; If the user master record belonging to user SAP* is deleted, it is possible to re-log on with SAP* and initial password PASS. SAP* then has the following attributes:&lt;/P&gt;&lt;P&gt;- The user has all authorization, as authorization check&lt;/P&gt;&lt;P&gt;   cannot be executed.&lt;/P&gt;&lt;P&gt;- You cannot change the standard password PASS.&lt;/P&gt;&lt;P&gt;Using profile parameter &amp;lt;b&amp;gt;login/no_automatic_user_sapstar&amp;lt;/b&amp;gt;,&lt;/P&gt;&lt;P&gt;you can deactivate the special attributes of SAP*.&lt;/P&gt;&lt;P&gt;So login to RZ11---&amp;gt;open the parameter(login/no_automatic_user_sapstar) and change the default Value to 1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Valid entries, formats, areas : 0, 1&lt;/P&gt;&lt;P&gt;0: Automatic user SAP* is permitted&lt;/P&gt;&lt;P&gt;1: Automatic user SAP* is deactivated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;Please award points if it is useful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;&lt;P&gt;Santosh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2007 10:21:20 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-r-3-security-problem/m-p/2252852#M487317</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-05-14T10:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: SAP R/3 security problem</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-r-3-security-problem/m-p/2252853#M487318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;b&amp;gt;Restricting SAP* and DDIC user&amp;lt;/b&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) First we change the password of &amp;lt;b&amp;gt;SAP*&amp;lt;/b&amp;gt; and &amp;lt;b&amp;gt;DDIC&amp;lt;/b&amp;gt; user in &amp;lt;b&amp;gt;SU01&amp;lt;/b&amp;gt; (T-code)&lt;/P&gt;&lt;P&gt;2) As &amp;lt;b&amp;gt;SAP&lt;STRONG&gt;&amp;lt;/b&amp;gt; is a hard coded user whenever SAP&lt;/STRONG&gt; user deleted, it is possible to re-log on with SAP* and initial password &amp;lt;b&amp;gt;PASS&amp;lt;/b&amp;gt;.&lt;/P&gt;&lt;P&gt;     Using profile parameter &amp;lt;b&amp;gt;login/no_automatic_user_sapstar&amp;lt;/b&amp;gt;, you can deactivate the special attributes of SAP*. &lt;/P&gt;&lt;P&gt;3) To avoid automatic generation SAP* password we set a profile parameter &amp;lt;b&amp;gt;login/no_automatic_user_sapstar=1(Automatic user SAP* is deactivated)&amp;lt;/b&amp;gt; in &amp;lt;b&amp;gt;RZ10&amp;lt;/b&amp;gt; (t-code).&lt;/P&gt;&lt;P&gt;4) Profile parameter will be effected only after restarting the sap system , so we restart sap system.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;kanthi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2007 12:40:11 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-r-3-security-problem/m-p/2252853#M487318</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-05-14T12:40:11Z</dc:date>
    </item>
  </channel>
</rss>

