SAP Security Note
High priority
SAP security note 1509753, "Webdocs: XSRF Protection for BSP Application WebDocuments", is a program error note released on 14.12.2010. Below are the symptom and the SAP recommended solution.
Description
Symptom
The XSRF protection provided by the BSP Framework is not adapted to the application WebDocuments, which is a BSP application.
Solution
- Implement corrections: Apply the corrections attached to this note. These corrections are valid for releases up to Ehp4 (604 for EA-APPL). For Ehp5 (605 for EA-APPL) and higher, the corrections are not applicable as the XSRF protection is enabled via the Workbench. Refer to Note 1505976.
- Additional information: Refer to Note 1520324 for additional information and instructions. The corrections from this note are a prerequisite for implementing Note 1509753.
- Execute report: Implement the correction instructions of this note. This will create the report
BSP_XSRF_PARAM_WEBDOCSin your system. - Run report: Execute the report
BSP_XSRF_PARAM_WEBDOCSand specify a corresponding transport request number when prompted. The report will populate the database tableBSPTEMPXSRFSTOREwith entries for the adapted BSP applications.
Reason and prerequisites
The application WebDocuments needed to adapt the XSRF protection provided by the BSP Framework/NetWeaver. Note 1505976 is a prerequisite.
References
- Note 1797045
- Note 1686627 – Unauthorized modification on document URL in PPM
- Note 1678243 – Unauthorized modification of BSP in WebDocuments (2)
- Note 1670098 – Unauthorized modification of BSP in WebDocuments
- Note 1540729 – ASU content for activating XSRF protection for BSP
- Note 1520324 – Advance creation of XSRF information
- Note 1505976 – Webdocs: Unauthorized Content Modification & Session Handling
Full note on SAP: SAP Support Launchpad note 1509753
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
