How to get rid of the technical help in the context menu of a Web Dynpro application.

For security reasons, users should not have access to the technical help from the ABAP Web Dynpro context menu. Sensitive data can get to unauthorized persons – especially if the web-based SAP application is accessible via the Internet. This is often the case with e-recruiting systems, for example.

For security reasons, users should not access technical help from the ABAP Web Dynpro context menu. Sensitive data can get to unauthorized persons – especially if the web-based SAP application is accessible via the Internet. This is often the case with e-recruiting systems, for example.

Wneb Dynpro Context Menü
ABAP Web Dynpro Context menu

There is an authorization problem.

If users in the production system have access to technical help, there is an authorization problem. To be more precise, the users are assigned the authorization object “S_DEVELOP”. If this authorization is revoked, the ‘technical help’ menu item disappears.

Locate causal roles

Find roles with the authorization object “S_DEVELOP” and the value “DEBUG“:

  • Start transaction “SUIM“.
  • Click “Roles by complex selection criteria“.
  • Search for the object “S_DEVELOP“.

SUIM
Rollen nach komplexen Selektionskriterien

Now check whether you can remove the authorization object from the roles via transaction “PFCG“. For security reasons, this authorization should be assigned in productive systems only in exceptional cases.

SAP Notes

For more information, see the following SAP Notes:

1846236 – WDA: How to hide/show the Technical help option in the context menu
783753 – Documentation for the S_DEVELOP authorization object

The Web Dynpro technology

Web Dynpro (WD) technology is used in web-based SAP applications. SAP continues to drive development forward. For example, current SAP releases use the HTML5 standard and touch-enabled user interfaces with Web Dynpro are now available.


SAP Patchday - Tönjes Consulting GmbH

Use the SecurityBridge SAP Patch Management, to never miss an important update for your SAP system again!

Contact us to learn more about SecruityBridge!


Contact us!