SAP Security Note
High priority
SAP security note 1524390, "XSRF Protection for Internet Kanban", is a note released on December 14, 2010. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can trigger functionality in the Internet Kanban without authentication and authorization.
Solution
- Prerequisite: ensure Note 1481392 is implemented.
- Implement the correction instructions relevant to your release. This action will create the report ITS_XSRF_PARAM_PK_500_605 in your system.
- Execute the ITS_XSRF_PARAM_PK_500_605 report and provide a transport order number when prompted. This report adds service parameters for the adjusted ITS services.
Reason and prerequisites
The Internet Kanban executes specific functions by referencing URLs. An attacker can trick an authenticated user’s browser into making a request with certain URLs and parameters, causing the function to execute with the user’s permissions. This can be achieved via a Cross-Site Scripting (XSS) attack or by presenting a clickable link to the victim.
Full note on SAP: SAP Support Launchpad note 1524390
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




