SAP Security Note
Medium priority
SAP security note 1517094, "CRM-IC: Session Access Token", is a program error note released on July 12, 2011. Below are the symptom and SAP recommended solution.
Description
Symptom
After implementing and activating security-relevant changes in SAP Netweaver (Note 1532777), the CRM Interaction cannot be started from the browser due to several communication issues, such as: CTI → Worker session, Agent session → Worker session, Browser polling / SAM communication → ICM or Worker Session.
Errors observed include: "400 Session not found", HTTPIO_USER_VALIDATION_SSOCOOKIE_MISSING (Note 1266780), HTTPIO_USER_VALIDATION_SSOCOOKIE_INVALID.
Solution
- Prerequisite: apply the correction from Note 1420203 (SAP_BASIS) to support Session Access Tokens.
- Implement the corrections attached to this note based on your system’s Support Package and CRMUIF, WEBCUIF, or SAP_ABA version. Important: if applying CRMUIF corrections, do not apply the SAP_ABA correction.
References
- 1521197 – Update #1 to Security Note 1517094
- 1865571 – HREIC: Phone Calls are not Received in EIC
- 1658516 – Applets fail due to XSRF protection (COOKIE_NOT_FOUND)
- 1301591 – HTTP 400 – Session not found (Stateful HTTP communication)
- 1266780 – User check for each HTTP request
Full note on SAP: SAP Support Launchpad note 1517094
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




