You are on page 1of 11

Skip to content Home General News Job Related blogs Consultants, Recruiters and Managers from Hell Consulting

blogs SAP Consulting Tips SAP News SAP Tips and Tricks Basis Tips Development Functional MM Materials Management SD Sales & Distribution SAP Data Load & Extracts SAP GRC SAP Security Biometrics Tips and Tricks Some fun stuff Fun to read

Homepage for SAP Professionals


SAP Community website with all sorts of interesting information related to SAP
Search here... Find

About Legal Career Center Contact us Newsletter SAP FAQ SAP Whitepapers Log In

Edit SAP tables: Your SAP Security Admins nightmare: &sap_edit


Nov 2 Basis Tips, Development, SAP Security, Tips and Tricks Last Update May 22, 2011

It does not matter what access you have for table editing (S_TABU_DIS). Just use the command &SAP_EDIT in the command field in SAP and off you go: you can edit table content directly. This works if you have debug with changes access for object S_DEVELOP, but S_TABU_DIS is ignored as well as the system settings regarding changes. If you use this function for transaction, master data or other tables that cannot be changed with SM30, you can cause quiet some damage. So, use with caution and this is NOT a Best Practice by all means, but to educate you on a little documented feature: Step 1: Use transaction UASE16N, SE16N or transaction N (yes, there is a transaction called just N) and enter a table of your choice, for example SKA1 G/L Account Master (Chart of Accounts)

2) In the command field enter &SAP_EDIT and press enter. The maintenance indicator in SE16N will switch on.

3) Limit the search of your data or execute for all values and you will see, that the table entries can be edited:

If you limit the users access not to have access to S_DEVELOP with change activities for object type DEBUG, this function will not be possible (tested on ECC5) If you want to allow this function, you can audit who changed data via SE16N by browsing the following tables; SE16N_CD_KEY : Change Documents Header

SE16N_CD_DATA : Change Documents Data You can also run report RKSE16N_CD via SE38 (or create a custom transaction for it for ease of use). We recommend to apply SAP Note 1420281 CO-OM tools: SE16N: Deactivating &SAP_EDIT. SAP will deliver this correction with Support Package 17 and Support Package 18 (Release 600). This note deactivates the SAP Support function &SAP_EDIT completely for SE16N Please make sure no users have access to transaction UASE16N as they may use it as alternative. Apply SAP Note 1473881 to disable UASE16N. Please leave a comment if you have tried this out: SAP note 1446530 enables one to use again the SE16n edit function on a case to case basis. As an authorization check it uses S_ADMI_FCD with field DBA. But wait, there is more. If your developers have access to SE38, SE80, SE37 and other development transactions, they may want to trick you by using SE37 and executing function module SE16N_INTERFACE with the options I_TAB, I_EDIT and I_SAPEDIT activated and still maintain tables. The good thing is, that these changes are recorded and can be viewed with report RKSE16N_CD, the bad thing is that it may be already too late if the users changes financial data or any other tables that are not supposed to be maintained via SE16 type of transactions. For starters, you should not give any development transactions to anyone outside the development environments and only allow SE37 etc. to be used via emergency procedures as once development access is granted, the users have the keys to the kingdom. Now, if you still want to give access to development transactions, you need to lock them down. For the Function Module SE16N_INTERFACE, you need to exclude activity 16 and Object name SE16N for object S_DEVELOP. Archiving: Consult OSS Note #1360465: Up to and including Release ECC604 you only have the option to use a report to delete these change documents (see Notes 1275614 and 1263844). To ensure a system can be checked, you must be able to document all changes. For this reason, Release ECC605 delivers archiving for the change document tables of SE16N. You can use the archiving object CA_SE16NCD to archive the change documents of SE16N. The write program permits you to make a restriction according to the date and the table names. To guarantee consistent archiving, we recommend you carry out archiving with date intervals only. Use the report RKSE16N_CD_DISPLAY to evaluate archives (and to display the documents found in the system). In the selection of the data source you can decide if the system reads from the database and/or from the archive. When reading the archive, we recommend you use the access in the archive information system (default setting). This post will be updated continuously due to the several issues with this function.

Rating: 4.7/5 (11 votes cast)

Share and Enjoy: &SAP_EDIT, audit, change, delete, direct update, edit, RKSE16N_CD, sap tables, se16, se16n, SE16N_INTERFACE, SOX, S_DEVELOP, S_TABU_DIS, tables, UASE16N, update Leave a comment Trackback Comments

Borut November 5th, 2010 at 11:52 PM This functionality is stopped ba SAP. It is no longer valid. Unfortunatelly.
Rating: +1 (from 1 vote)

Borut November 6th, 2010 at 12:02 AM You can use only FM SE16N_INTERFACE.
Rating: 0 (from 2 votes)

a February 3rd, 2011 at 2:48 PM thanks fo the tips!


Rating: 0 (from 0 votes)

Arieh May 22nd, 2011 at 4:28 AM How can we Archive / delete entries in SE16N_CD_DATA and SE16N_CD_KEY . SE16N_CD_DATA is now 18 GB in our system.
Rating: +1 (from 1 vote)

Webmeister May 22nd, 2011 at 11:38 AM Consult OSS Note 1360465: You can use the archiving object CA_SE16NCD to archive the change documents of SE16N. The write program permits you to make a restriction according to the date and the table names. To guarantee consistent archiving, we recommend you carry out archiving with date intervals only. Use the report RKSE16N_CD_DISPLAY to evaluate archives (and to display the documents found in the system). In the selection of the data source you can decide if the system reads from the database and/or from the archive. When reading the archive, we recommend you use the access in the archive information system (default setting).
Rating: +2 (from 2 votes)

Leave a Reply
Name (required) Mail (will not be published) (required) Website

Leave comment

Our anti spam software captures 100% of comment spam. Contact us if your comment doesn't appear within 2 business days as we moderate all comments that made it through our anti-spam software. No proxy postings allowed. Blocked comments to date:
986

spam c omments

Number of people wasting time entering spam comments:


189

Spam P rotection by WP -SpamFree

RSS feed for this post (comments)

Popular Posts (last 30 days)


Edit SAP tables: Your SAP Security Admins nightmare: &sap_edit 311 view(s) How to Create a Transaction Code for Report Painter Reports 198 view(s) ECC5.0 ALV default file format when extracting files to Excel 186 view(s) customer Master Customization in SAP SD 163 view(s) Quicktip: How to delete developer keys from SAP 132 view(s) Protecting Standard Users 106 view(s) User cannot save layout in VA05 103 view(s) Create custom transaction for SE16 94 view(s) Quick Tip: Decimal Notation / Date Format in SU01 94 view(s) Text Determination in SAP SD 92 view(s)

Legal Notice
Copyright Notice Original author(s) retain their own copyright(s). Original content is Copyrighted by Home4SAP.com. Any original home4sap.com content may be freely redistributed or posted in part or in full with full attribution to the original post, through a direct link to the original post. Pursuant to Title 17 U.S.C. 107, other copyrighted work is provided for educational purposes, research, critical comment, or debate without profit or payment. If you wish to use copyrighted material from this site for your own purposes beyond the 'fair use' exception, you must obtain permission from the copyright owner. Legal Disclaimer This site is not affiliated with, endorsed by, nor operated in conjunction with SAP, any of its affiliates, subsidiaries, partners or those who have a direct relationship with the company. For more information from SAP, please visit the company site at: http://www.sap.com/ Please note, all articles, submissions, or other information that does not come directly from SAP is opinion and suggestion. In practice, actual results, or particular tasks and steps may vary depending on your unique situation or circumstances. The author reserves the right to correct, update, alter, modify, or remove any articles or other content on the site as circumstances may warrant. No warranty or guarantee of any kind, express or implied, is offered for any information contained within this site. You must carefully consider any actions you take within the context of the specific situation and circumstances of the environment you are applying them.

Application Integration
Code Free, Application Integration Download Free Trial Now.
www.Autom ationAnywhe re .com

Homepage for SAP Professionals Homepage for SAP Professionals

Sign up for our weekly newsletter with the latest blogs

Advertising

sap4u.org

SAP , , ,
www.sap4u.org

-
,!
Halafim .Galgalim .co.il

Comax

ERP ,
www.C om ax -C loud.com


,
www.iscs.co.il

BI MAKE SENSE

, ,
www.se nse it.co.il

Free Magazine!
This is a free magazine selected for the valued visitors of this blog. Subscribe now!

Business Cards offer


Special offer for Home4SAP.com visitors only! Order today and save up to 80%! Hurry - Limited time offer! Click the business card below for details!

Search SAP Jobs


Enter Keyword(s):

Enter a City: Select a State:

All United States


Select a Category:

All Job Categories Search

- Advanced Job Search - Search by Company

Categories
General News (5) Job Related blogs (38) Consultants, Recruiters and Managers from Hell (2) Consulting blogs (7) SAP Consulting Tips (21) SAP News (8) SAP Tips and Tricks (72) Basis Tips (11) Development (11) Functional (10) MM Materials Management (1) SD Sales & Distribution (4) SAP Data Load & Extracts (6)

SAP Data Load & Extracts (6) SAP GRC (23) SAP Security (9) Biometrics (1) Tips and Tricks (17) Some fun stuff (5) Fun to read (3)

Wolfam|Alpha
computational knowledge engine

Links
Add Add Davatec Consulting, Inc. Home for SAP Professionals SAP Directory SAP Geek SAP Jobs SAP Tutorials (Spanish)

Archive
Select Month

Users Online
Users: 5 Guests

SAP Network Blog


Key EIM and Information Governance sessions for SAP TechEd 2011 August 8, 2011 There are nearly a zillion SAP TechEd sessions. This blog outlines pre-conference, hands-on, lecture, expert networking, and pod topics for all of you data wonks out there. [] Information Governance Tips + Tricks from a Practitioner August 8, 2011 SAPs Maria Villar is leading a series of Information Governance workshops, co-sponsored by Deloitte. Learn a few highlights around forming your program, securing executive sponsorship, and finding data quality tales of woe. [] SCNotty Goes To Bollywood August 7, 2011 Do you have a minute to record yourself on video and post it online? Are you going to SAP

Do you have a minute to record yourself on video and post it online? Are you going to SAP TechEd in Bangalore this year? If you answered yes to both, join me as we take the world famous SCNotties awards to the Indian subcontinent. []

Copyright 2011 Homepage for SAP Professionals Design by SRS Solutions top
WordPress SEO fine-tune by Meta SEO Pack from Poradnik Webmastera
SAP is a registered trademark of SAP AG in Germany and in several other countries. The Homepage for SAP Professionals is not affiliated to SAP AG or any of its subsidiaries.