SAP security note 646140, "Security Check of Internet Sales". Below are the symptom and SAP recommended solution.
Description
Symptom
You want to secure your Internet Sales application.
Solution
This note provides information on how to secure the Internet Sales application. Follow the steps below to enhance the security of your system:
- Protecting Internet Sales (ISA) Administration Pages:
- Creating a New User for ISA Administration: Create a new user on the J2EE engine and allow only this user to access the ISA administration pages. See Note 502803
- Changing Password of J2EE Engine Administrator: The Administrator user must not be used for accessing the ISA administration pages. Ensure the password of the Administrator is different from the password of the user accessing the ISA pages. See Note 603142
- Restricting Access to ISA Administration Pages from the Internet: Limit access to the ISA administration pages to prevent unauthorized internet access. See Note 675049. If using Apache HTTP server, refer to Note 708138.
- Turning Off Further Features of the Administration Pages: Disable additional features as described in Note 645923. In ISA 4.0 SP06 or higher, the following features are turned off: appinfo and logfiledownload.
- Securing Files Containing Sensitive Data After Deployment: Secure files that contain sensitive data, such as logon data to the CRM system. See Note 675125
- Logging/Tracing:
- Turning Off Tracing in Productive Systems: Set the trace level to ERROR to minimize logging in productive environments. Refer to the CRM E-Selling: Business Scenario Configuration Guide for more details.
- Handling RFC Tracing in ISA: Ensure that sensitive data is not traced when enabling RFC tracing for any function module. See Note 644288
- Disabling ‘showstacktrace’ Feature in Productive Systems: Prevent disclosure of stack traces by turning off the showstacktrace feature. See Note 702408
- Applying Security Relevant Patches:
- B2C:
- 624393 – Sales order of other users can be displayed authentication
- 625135 – CRM ABAP solution: Display orders of other users
- 625402 – ‘Remote-enabled’ flag for CRM_ISA_BASKET_GETPAYMENT
- 627649 – Credit card data is stored in the log file
- 725954 – Features having impact on Security are disabled in LWC
- B2B R/3 Edition:
- 827869 – Logging of JCO Password in R3CatalogServerEngine
- B2C:
- Restricting Access to Shop Administration Application in R/3 Scenario: See Note 693832
- SAP J2EE Engine 6.20:
- Turning Off HTTP Based File Browsing: See Note 531495
- Collective Security Note: See Note 606733
- Applying Mandatory Patches: See Note 705619
References
- 1244194 – Extended security enhancements in the application isauseradm
- 1164539 – Extended security enhancements to prevent XSS vulnerability
- 856175 – Access to protected resources may be granted
- 755934 – CRM 3.1 SP Stack 07/2004 (SAPKU31009): Release & Info. Note
- 675125 – Securing files containing sensitive data
Full note on SAP: SAP Support Launchpad note 646140
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



