2007 Jun 25 2:22 PM
Hi all,
I'm not sure if anyone can be of help but here goes.
During an Audt of a SAP Basis implementation when checking the the table SM59 we came across a user SAP_UPGRADE_SHADOW_SYSTEM. It was found that there was no password or user associated with this. I can email the print screen to anyone if that helps.
What we are trying to determine is whether or not this poses any threat to the system. If anyone has any idea about this any help would be fantastic.
Cheers
2007 Jun 25 2:28 PM
John,
SAP_UPGRADE_SHADOW_SYSTEM is the SM59 RFC destination for setting up an SAP shadow system. It usually uses the ID DDIC in client 000. I would check with your basis team regarding this RFC connection.
Cheers,
Ben
Hi all,
I'm not sure if anyone can be of help but here goes.
During an Audt of a SAP Basis implementation when checking the the table SM59 we came across a user SAP_UPGRADE_SHADOW_SYSTEM. It was found that there was no password or user associated with this. I can email the print screen to anyone if that helps.
What we are trying to determine is whether or not this poses any threat to the system. If anyone has any idea about this any help would be fantastic.
Cheers
2007 Jun 25 2:28 PM
John,
SAP_UPGRADE_SHADOW_SYSTEM is the SM59 RFC destination for setting up an SAP shadow system. It usually uses the ID DDIC in client 000. I would check with your basis team regarding this RFC connection.
Cheers,
Ben
2007 Jun 25 2:37 PM
Hi, Part of the problem is that I don't have access to the system as its a clients system that was audited. I can send you the print screen I have if you feel that could be any help. Thanks
2007 Jun 25 2:45 PM
Heres basically what the client had to say and i've to try find out if this is valid or not. The guy working on this is on holidays and we need to have answers by tomorrow.
"There appears to be confusion on the part of the auditors between the SAP_UPGRADE_SHADOW_SYSTEM and the SAP_UPGRADE_SHADOW_SYSTEM <b>rfc</b>. The fing alleges that the absence of a password on SAP_UPGRADE_SHADOW_SYSTEM could allow access through RFC from table RFCDES to another system (presumably production). This is factually incorrect.
SAP_UPGRADE_SHADOW_SYSTEM existed only for the duration of the now complete upgrade, and was not present during the audit. The SAP_UPGRADE_SHADOW_SYSTEM <b>rfc</b> was present in the production system, but access to any other system using it would have required passing through all of the security controls on the SAP production, QA or DEV systems. Even then it is not clear what "other" R/3 system might have been accused in this way, or what "communication or interface" could have taken place."
Thats what their manager is saying but I personally don't have the knowledge of SAP to know whether or not this is valid. Thanks
2007 Jun 25 2:50 PM
If it's not a trusted RFC connection and there is no ID or password in the RFC Destination than anyone who logs on through that connection will need to pass that system's controls.
Cheers,
Ben
2007 Aug 27 10:19 PM
Hi John,
If your client is doing "housekeeping" to clean up RFC connections, then that would be a good thing.
If you are offering screenshots of your client's RFC connections in the internet, then I would class that as a bad idea.
Cheers,
Julius