12.07.2015 Views

Avoiding Compliance Issues in ABAP code - Virtual Forge

Avoiding Compliance Issues in ABAP code - Virtual Forge

Avoiding Compliance Issues in ABAP code - Virtual Forge

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Risks of SQL Injection (APP-06)Exemplary Analysis of a technical Risk• PPT Illegal MasterfolieAccess to data of another SAP Client• zur Manipulation Erstellung of User von Accounts Präsentationenand Authorizations (SOX Violation)• E.g. assign SAP_ALL Rights to unauthorized Users• Undocumented Changes to critical Tables (SOX Violation)• No Entries <strong>in</strong> CDHDR, CDPOS, …• Read Access to HR Data (Violation of Data Protection Law)• E.g. Social Security Number (PA0002-PERID)• Access to Credit Card Data (PCI/DSS Violation)• E.g. BSEGC-CCNUM• Access to Bank Account Data of Customers and Suppliers• E.g. Customer Bank Data (KNBK-BANKN)• Manipulation von f<strong>in</strong>ancial Data (SOX Violation)• E.g. Manipulation of Table BSEG© 2012 <strong>Virtual</strong> <strong>Forge</strong> GmbH | www.virtualforge.com | All rights reserved.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!