Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

XSRF protection for internet kanban, SAP security note 1524390

SAP Note 1524390
SAP Security Note
High priority

SAP security note 1524390, "XSRF Protection for Internet Kanban", is a note released on December 14, 2010. Below are the symptom and SAP recommended solution.

ComponentProduction Planning and Control > KANBAN (PP-KAB)
PriorityCorrection with High Priority
TypeSAP Security Note
Version6
StatusReleased for Customer
Released onDecember 14, 2010

Description

Symptom

A malicious user can trigger functionality in the Internet Kanban without authentication and authorization.

Solution

  • Prerequisite: ensure Note 1481392 is implemented.
  • Implement the correction instructions relevant to your release. This action will create the report ITS_XSRF_PARAM_PK_500_605 in your system.
  • Execute the ITS_XSRF_PARAM_PK_500_605 report and provide a transport order number when prompted. This report adds service parameters for the adjusted ITS services.

Reason and prerequisites

The Internet Kanban executes specific functions by referencing URLs. An attacker can trick an authenticated user’s browser into making a request with certain URLs and parameters, causing the function to execute with the user’s permissions. This can be achieved via a Cross-Site Scripting (XSS) attack or by presenting a clickable link to the victim.

Full note on SAP: SAP Support Launchpad note 1524390

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More